Description
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
Published: 2026-09-04
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

A local authenticated attacker who can use SSH on IBM i systems can read privileged files and obtain sensitive information. The vulnerability corresponds to CWE‑267.

Affected Systems

IBM i versions 7.5 and 7.6 are affected. IBM releases a fix as part of Release5733‑SC1, with PTF SJ11404 for 7.6 and PTF SJ11405 for 7.5.

Risk and Exploitability

The CVSS score of 3.3 places the risk in the low range, and an EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting limited or no known exploitation. The attack vector requires local authentication; therefore, it cannot be exploited remotely and poses a lower threat to systems without compromised accounts.

Generated by OpenCVE AI on September 4, 2026 at 19:10 UTC.

Remediation

Vendor Solution

IBM i Release5733-SC1  PTF Number(s)PTF Download Link(s)7.6SJ11404 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11404 7.5SJ11405 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11405 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5733‑SC1 patches: PTF SJ11404 for 7.6 and PTF SJ11405 for 7.5.
  • Restrict local SSH access by removing unnecessary user accounts and enforcing least‑privilege policies on privileged files.
  • Ensure that privileged files have appropriate permissions and are not readable by non‑trusted local accounts.
  • If the system is running an unsupported IBM i edition, plan an upgrade to a supported release that includes the patch.

Generated by OpenCVE AI on September 4, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
Title IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH []
First Time appeared Ibm
Ibm i
Weaknesses CWE-267
CPEs cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-08T17:16:19.459Z

Reserved: 2026-08-04T16:06:12.417Z

Link: CVE-2026-18858

cve-icon Vulnrichment

Updated: 2026-09-08T17:16:15.450Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T16:17:21.270

Modified: 2026-09-08T21:37:00.200

Link: CVE-2026-18858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T00:00:06Z

Weaknesses
  • CWE-267

    Privilege Defined With Unsafe Actions