Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
Published: 2026-09-29
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a locally authenticated attacker to change the ownership of arbitrary files on IBM i systems due to improper validation of an attacker‑controlled file path. This flaw falls under an incorrect permission assignment and could enable the attacker to gain additional privileges, modify sensitive files or data, and compromise the integrity of the system. The description does not indicate any remote or network‑level exploitation, so the impact is limited to local users with sufficient authentication.

Affected Systems

IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. The vendor provides specific patch notes for each release, and the official remedy is to apply the corresponding IBM i Release5770‑SS1 update or the release‑specific PTFs (SJ11607 for 7.6, SJ11608 for 7.5, SJ11609 for 7.4, and SJ11610 for 7.3).

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as High severity. EPSS information is not available, so exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local authenticated user who can choose file paths; there is no indication of exploitation across a network or via a remote service. The risk is consequently high within systems that allow local authentication, but it does not extend to remote attackers.

Generated by OpenCVE AI on September 29, 2026 at 23:24 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ11607 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11607 7.5SJ11608 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11608 7.4SJ11609 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11609 7.3SJ11610 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11610 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i patch that matches your release (SJ11607 for 7.6, SJ11608 for 7.5, SJ11609 for 7.4, or SJ11610 for 7.3).
  • If you are running an unsupported IBM i release, upgrade to IBM i Release5770‑SS1 or a newer supported release that includes the fix.
  • Enable auditing of file ownership changes and limit local user privileges until the patch is applied.

Generated by OpenCVE AI on September 29, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
Title IBM i is Affected By An Incorrect Permission Assignment Vulnerability in Network Authentication Service []
First Time appeared Ibm
Ibm i
Weaknesses CWE-732
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-29T19:52:28.974Z

Reserved: 2026-09-01T17:35:17.124Z

Link: CVE-2026-84414

cve-icon Vulnrichment

Updated: 2026-09-29T19:52:23.522Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:17.400

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-84414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T23:30:19Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource