Sceawere
Vulnerability Detail
CVE-2026-13433UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i ACS Unverified Update Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.3
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- i Access Client Solutions
- Attack Type
- CWE-494 Download of Code Without Integrity Check
- Vector String
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.3",
"pubDate": "2026-08-12T21:17:35.380Z",
"pubdate": "2026-08-12T21:17:35.380Z",
"executiveSummary": "IBM i Access Client Solutions (ACS) versions 1.1.2.0 through 1.1.9.13 contain an insecure update mechanism vulnerability. The flaw exists in the product update feature when configured to retrieve updates directly from an IBM i server. This vulnerability allows an unauthenticated or privileged attacker with network or server access to facilitate the download and execution of arbitrary, unverified product code on a client workstation running the ACS software. Successful exploitation leads to arbitrary code execution within the context of the user running IBM i Access Client Solutions, potentially compromising the integrity and confidentiality of the target workstation. The attack capability relies on the client's implicit trust in update payloads retrieved from the configured IBM i update source without cryptographic signature validation or integrity checks. Mitigation requires administrative intervention to secure update repositories or disable automated update configurations pending vendor patches.",
"technicalDetails": "The vulnerability resides within the automated update mechanism of IBM i Access Client Solutions (ACS) versions 1.1.2.0 through 1.1.9.13. Specifically, when the client application is configured to check for and download software updates from a designated IBM i host, it fails to cryptographically verify the authenticity, integrity, and provenance of the retrieved product code, binaries, or update packages before execution.\nThe root cause of this vulnerability is the absence of digital signature verification, certificate validation, or secure checksum validation on the downloaded update payloads prior to local staging and execution. The client blindly trusts the update source configured within the environment.\nThe step-by-step attack flow involves an adversary leveraging network positioning, compromised server privileges, or storage manipulation on the designated IBM i update source. When the targeted ACS user initiates or permits an update check, the client application queries the configured IBM i server for available updates. The malicious actor intercepts or replaces legitimate update payloads residing on the IBM i update repository with compromised product code. The ACS client downloads the unverified malicious payload onto the local workstation. Upon completion of the download, the ACS application executes the staging installer or binary packages. Because the client lacks verification controls, the compromised code executes natively on the workstation.\nThe vulnerable component is the update subsystem of IBM i Access Client Solutions. Affected versions include 1.1.2.0 up to and including 1.1.9.13. Exploitation typically requires the client to be configured for IBM i-based updates and an adversary to have the capability to modify update files on the target IBM i system or perform adversary-in-the-middle manipulations depending on the protocol used for retrieval.\nThe post-exploitation impact includes arbitrary code execution on the ACS user's workstation, allowing the attacker to inherit the privileges of the local user account, access sensitive system resources, deploy secondary payloads, or pivot further into connected network segments."
}