Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
Published: 2026-08-12
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a remote authenticated attacker to bypass security restrictions due to improper authorization in IBM i. The flaw is classified as CWE-285, indicating that the system fails to enforce correct authorization checks, potentially letting an attacker elevate privileges or access protected resources beyond intended permissions.

Affected Systems

Affected products are IBM i versions 7.6, 7.5, 7.4, and 7.3. The corresponding IBM PTFs to remediate the flaw are SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, and SJ10891 for 7.3. All identified CPEs reflect these versions.

Risk and Exploitability

The CVSS score of 4.3 reflects a moderate impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote authenticated user exploiting the lack of proper authorization checks, which could allow unauthorized privilege escalation or data access if not mitigated promptly.

Generated by OpenCVE AI on August 12, 2026 at 23:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ10887 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10887 7.5SJ10888 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10888 7.4SJ10890 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10890 7.3SJ10891 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10891 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTF corresponding to your version (for example, applying SJ10887 on 7.6, SJ10888 on 7.5, SJ10890 on 7.4, or SJ10891 on 7.3) to fix the improper authorization flaw.
  • If your environment still runs an unsupported IBM i release, upgrade to a supported release that includes the fix.
  • Review and tighten user access controls by removing unnecessary accounts and enforcing the principle of least privilege to prevent authenticated users from bypassing restrictions.

Generated by OpenCVE AI on August 12, 2026 at 23:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Wed, 12 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
Title IBM i is Affected By Multiple Vulnerabilities in Navigator for i
First Time appeared Ibm
Ibm i
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-12T17:52:24.745Z

Reserved: 2026-07-28T18:55:21.853Z

Link: CVE-2026-18144

cve-icon Vulnrichment

Updated: 2026-08-12T17:52:12.492Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T17:17:25.247

Modified: 2026-08-17T14:39:25.557

Link: CVE-2026-18144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:45:03Z

Weaknesses