Description
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
Published: 2026-08-12
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated attacker who can place a script on an IBM i system can trigger the activation engine component to execute that script with superuser privileges. This grants full control over the affected host, allowing the attacker to modify system files, compromise services, or establish persistence. The flaw is a classic privilege escalation via remote code execution, classified as CWE‑250.

Affected Systems

IBM i versions 7.3, 7.4, 7.5, and 7.6 are affected. The fix is supplied through IBM’s Problem Tracking Facility downloads: SJ11009 for 7.6, SJ10978 for 7.5, SJ10977 for 7.4, and SJ10976 for 7.3. Administrators running unsupported or older releases should plan an upgrade to the latest supported IBM i release.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating high severity and high impact. Though no EPSS score is available and it is not listed in CISA KEV, the high score warrants immediate attention. The exploit requires authenticated access, so it is most likely to be leveraged by attackers who have legitimate or stolen credentials. Once privilege escalation to root is achieved, any subsequent attack becomes trivially feasible. IBM strongly recommends applying the PTF immediately and there is no temporary workaround.

Generated by OpenCVE AI on August 12, 2026 at 22:44 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11009https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11009 7.5SJ10978https://www.ibm.com/mysupport/s/fix-information?legacy=SJ109787.4SJ10977https://www.ibm.com/mysupport/s/fix-information?legacy=SJ109777.3SJ10976https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10976IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTF that applies to your release (for example, SJ11009 for 7.6 or SJ10978 for 7.5) via the IBM Fix Central portal.
  • Ensure your system is running a supported IBM i release; if you are on an unsupported version, upgrade to the latest supported release before or after applying the PTF.
  • Reduce exposure by limiting which users can place scripts in directories that trigger the activation engine; consider disabling the component temporarily until the fix is installed.

Generated by OpenCVE AI on August 12, 2026 at 22:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
Title IBM i is Affected By A Privilege Escalation Vulnerability []
First Time appeared Ibm
Ibm i
Weaknesses CWE-250
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-12T19:18:06.023Z

Reserved: 2026-08-03T14:49:31.412Z

Link: CVE-2026-18669

cve-icon Vulnrichment

Updated: 2026-08-12T17:57:36.906Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T18:17:28.723

Modified: 2026-08-12T20:53:43.330

Link: CVE-2026-18669

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T22:45:10Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges