Description
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
Published: 2026-08-28
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a flaw in the IBM Administration Runtime Expert for i (ARE) GUI component that permits an unauthenticated remote attacker to obtain the privilege level of another authenticated user. By leveraging this weakness the attacker can perform system actions, access, or modify data with the privileges of the compromised user, thereby compromising the integrity, confidentiality, and availability of the IBM i system.

Affected Systems

The flaw affects IBM Administration Runtime Expert for i version 1R1M0 (release 5733‑ARE) deployed on IBM i operating systems. The affected component is the ARE GUI. The recommended fix is the IBM PTF SJ11185, which after installation disables the legacy ARE GUI until the underlying security issue is resolved.

Risk and Exploitability

The vulnerability has a CVSS v3 score of 9.9, classifying it as critical. The EPSS score is unavailable, and it is not listed in the CISA KEV catalog. The attacker does not need prior authentication; based on the description, it is inferred that the attacker may send crafted requests to the ARE GUI component to trigger the privilege escalation. Successful exploitation grants arbitrary elevation to any user profile on the IBM i system, potentially allowing full system compromise. The high severity and lack of detection mechanisms make this a high‑risk vulnerability that warrants immediate remediation.

Generated by OpenCVE AI on August 29, 2026 at 00:05 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Release5733-ARE PTF Number(s)PTF Download Link(s)V1R1M0 SJ11185 After applying this PTF the legacy ARE GUI is nonfunctional. https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11185


OpenCVE Recommended Actions

  • Apply the IBM PTF SJ11185 to the affected IBM i system immediately.
  • If legacy ARE GUI functionality must remain operational until the patch is deployed, temporarily disable or restrict access to the ARE GUI component.
  • Enforce network segmentation around the IBM i environment and monitor system logs for suspicious privilege‑escalation activity after the patch has been applied.

Generated by OpenCVE AI on August 29, 2026 at 00:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
Title IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].
First Time appeared Ibm
Ibm administration Runtime Expert For I
Weaknesses CWE-384
CPEs cpe:2.3:a:ibm:administration_runtime_expert_for_i:1r1m0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm administration Runtime Expert For I
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Administration Runtime Expert For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:48:33.957Z

Reserved: 2026-07-31T19:47:47.809Z

Link: CVE-2026-18527

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:46.620

Modified: 2026-08-28T22:16:46.620

Link: CVE-2026-18527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses