Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
Published: 2026-09-04
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Remote Access
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises when IBM i DDM/DRDA improperly validates client‑supplied authentication parameters, allowing a remote attacker to authenticate without proper credentials and potentially gain full system access. This flaw is an instance of Improper Authentication (CWE‑287).

Affected Systems

IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. The flaw impacts the DDM/DRDA interfaces. PTFs such as SJ11230, SJ11231, SJ11232, SJ11233, SJ11234, SJ11235, SJ11261, and SJ11262 address the vulnerability for the corresponding release levels.

Risk and Exploitability

The CVSS score is 8.1, indicating high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, so no known exploitation in the wild has been reported. The attack vector is remote and network‑based, as the flaw exists in a protocol exposed by DDM/DRDA. An attacker must supply crafted authentication parameters, suggesting that connections from untrusted networks could be exploited if no mitigation is applied.

Generated by OpenCVE AI on September 4, 2026 at 18:15 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ11231 SJ11230 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11231 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11230 7.5SJ11232 SJ11233 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11232 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11233 7.4SJ11262 SJ11261 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11262 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11261 7.3SJ11234 SJ11235 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11234 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11235 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Install the IBM i PTFs listed in the official solution (SJ11230, SJ11231, SJ11232, SJ11233, SJ11234, SJ11235, SJ11261, SJ11262) for the affected IBM i releases.
  • If the system runs an unsupported IBM i version, upgrade to a supported release that contains the fixed PTFs.
  • Restrict access to the DDM/DRDA service to trusted hosts or networks to limit the exposure surface.

Generated by OpenCVE AI on September 4, 2026 at 18:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
Title IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-08T17:22:39.764Z

Reserved: 2026-07-29T10:16:45.385Z

Link: CVE-2026-18221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:56.150

Modified: 2026-09-08T19:40:12.663

Link: CVE-2026-18221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T21:15:04Z

Weaknesses