Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.
Published: 2026-08-13
Score: 4.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i versions 7.6, 7.5, 7.4, and 7.3 contain a flaw in the Java Secure Sockets Extension that allows a local attacker to trigger an improper bounds check, which can lead to arbitrary code execution or cause the system to crash. The vulnerability is limited to users who have local access to the affected IBM i operating system and does not provide remote exploitation vectors.

Affected Systems

Affected products are IBM i running versions 7.6, 7.5, 7.4, and 7.3. For each release, IBM has issued a set of patches, including PTFs such as SJ11036, SJ11072, SJ11082, SJ11088 for 7.6, along with corresponding PTFs for the earlier releases. Users running unsupported versions should consider upgrading to a supported, fixed release.

Risk and Exploitability

The CVSS score of 4.5 reflects moderate security risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector is a local attacker with sufficient privileges to apply patches or execute code on the IBM i system.

Generated by OpenCVE AI on August 13, 2026 at 22:40 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-JV1 PTF Number(s)PTF Download Link(s)7.6SJ11036 SJ11072 SJ11082 SJ11088 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11036 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11072 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11082 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11088 7.5SJ11068 SJ11073 SJ11070 SJ11077 SJ11087 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11068 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11073 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11070 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11077 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11087 7.4SJ11071 SJ11069 SJ11076 SJ11086 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11071 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11069 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11076 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11086 7.3SJ11067 SJ11075 SJ11085 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11067 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11075 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11085 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTFs provided by IBM (e.g., SJ11036, SJ11072, SJ11082, SJ11088 for 7.6 and the analogous PTFs for 7.5, 7.4, and 7.3) to fix the bounds checking flaw.
  • After installing the patches, reboot the IBM i system or restart affected services to ensure the fixes take effect.
  • If your system is still running an unsupported version, plan an upgrade to a supported IBM i release that includes the security updates.

Generated by OpenCVE AI on August 13, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.
Title IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:42:13.240Z

Reserved: 2026-07-28T15:56:38.935Z

Link: CVE-2026-18086

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:44.377

Modified: 2026-08-13T21:17:44.377

Link: CVE-2026-18086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T02:00:14Z

Weaknesses