Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
Published: 2026-08-13
Score: 8.9 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i versions 7.6, 7.5, 7.4, and 7.3 contain a flaw that allows a remote attacker to bypass security restrictions by providing improperly validated user-controlled addresses. This vulnerability is an instance of improper authorization (CWE-269). The flaw can potentially allow the attacker to gain higher privileges or execute arbitrary code within the affected IBM i environment, compromising confidentiality, integrity, and availability of the system.

Affected Systems

Affected systems include IBM i Release 7.6, 7.5, 7.4, and 7.3. Specific PTFs addressed by IBM for each release are: for 7.6 – SJ11037, SJ11013, SJ11065, SJ11078; for 7.5 – SJ10990, SJ11014, SJ11042, SJ11066, SJ11080; for 7.4 – SJ11016, SJ11041, SJ11064, SJ11081; for 7.3 – SJ11040, SJ11063, SJ11079. Users should ensure their IBM i installations are updated with these patches to eliminate the vulnerability.

Risk and Exploitability

The vulnerability scores a CVSS of 8.9, indicating high severity, and it is not listed in the CISA KEV catalog, but the EPSS score is not available, suggesting limited public exploitation data. Nevertheless, the flaw permits a remote attacker to influence the system by feeding crafted addresses that bypass security checks. Attackers would need network access to the IBM i system and could exploit the vulnerability through exposed services that accept address input, potentially leading to privilege escalation or arbitrary code execution. Given the high CVSS and the lack of existing mitigation, the risk remains significant.

Generated by OpenCVE AI on August 13, 2026 at 22:39 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-JV1 PTF Number(s)PTF Download Link(s)7.6SJ11037 SJ11013 SJ11065 SJ11078 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11037 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11013 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11065 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11078 7.5SJ10990 SJ11014 SJ11042 SJ11066 SJ11080 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10990 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11014 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11042 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11066 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11080 7.4SJ11016 SJ11041 SJ11064 SJ11081 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11016 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11041 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11064 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11081 7.3SJ11040 SJ11063 SJ11079 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11040 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11063 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11079 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTFs listed for your release (e.g., SJ11037, SJ11013, SJ11065, SJ11078 for 7.6; SJ10990, SJ11014, SJ11042, SJ11066, SJ11080 for 7.5; SJ11016, SJ11041, SJ11064, SJ11081 for 7.4; SJ11040, SJ11063, SJ11079 for 7.3).
  • If patching cannot be performed immediately, isolate the affected IBM i systems from untrusted networks and restrict access to services that accept user-supplied addresses.
  • Enable logging and monitoring of authentication and authorization events to detect any attempts to exploit address validation weaknesses.

Generated by OpenCVE AI on August 13, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
Title IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime
First Time appeared Ibm
Ibm i
Weaknesses CWE-269
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:42:46.558Z

Reserved: 2026-07-29T03:32:13.335Z

Link: CVE-2026-18193

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:44.700

Modified: 2026-08-13T21:17:44.700

Link: CVE-2026-18193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management