Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management.
Published: 2026-08-13
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local attacker can increase their privileges on IBM i systems by exploiting improper privilege management (CWE-269) in the HTTP Server component. The flaw allows the attacker to gain elevated rights that can be used to execute arbitrary actions affecting the confidentiality and integrity of the system.

Affected Systems

IBM i releases 7.3, 7.4, 7.5 and 7.6 are affected. The recommended PTFs are SJ11138 for 7.3, SJ11137 for 7.4, SJ11136 for 7.5 and SJ11135 for 7.6. These patches address the improper privilege handling.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity issue. Because exploitation requires local access, the likelihood of attack depends on the presence of a threat actor with physical or local network access. The vulnerability is not currently listed in the CISA KEV catalog and no EPSS value is available, so the exact exploitation probability is uncertain, but the potential for severe impact warrants prompt remediation.

Generated by OpenCVE AI on August 13, 2026 at 21:36 UTC.

Remediation

Vendor Solution

IBM i Release5770-DG1  PTF Number(s)PTF Download Link(s)7.6SJ11135 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11135 7.5SJ11136 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11136 7.4SJ11137 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11137 7.3SJ11138 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11138 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the PTF corresponding to your IBM i version (SJ11135 for 7.6, SJ11136 for 7.5, SJ11137 for 7.4, or SJ11138 for 7.3).
  • After applying the PTF, restart the HTTP Server service to ensure the patch is in effect.
  • If your IBM i release is unsupported, upgrade to a supported version such as IBM i Release5770-DG1 to receive ongoing security updates.

Generated by OpenCVE AI on August 13, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management.
Title IBM i is Affected By An Improper Management Vulnerability in HTTP Server []
First Time appeared Ibm
Ibm i
Weaknesses CWE-269
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T18:48:31.331Z

Reserved: 2026-07-28T15:04:08.065Z

Link: CVE-2026-18071

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-13T19:17:18.970

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-18071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management