Sceawere

Vulnerability Detail

CVE-2026-14276UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Access Macro Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
IBM
Product
i Access Family
Attack Type
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-09-14T21:17:02.413Z",
  "pubdate": "2026-09-14T21:17:02.413Z",
  "executiveSummary": "This vulnerability is an improper input validation flaw affecting IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.15. The issue resides within the emulator macro handling mechanism, specifically the 'RunProgram' action. An authenticated, local user can exploit this weakness to achieve arbitrary command execution under their own privilege level. This poses a significant security risk by enabling the execution of unauthorized system commands, scripts, or binaries via maliciously crafted emulator macro files. Successful exploitation requires the attacker to be authenticated to the system and capable of deploying or influencing a macro file used by the IBM i Access Client Solutions interface. The vulnerability facilitates a vector for privilege abuse, potentially leading to unauthorized configuration changes or the execution of malicious payloads that leverage the existing session environment.",
  "technicalDetails": "The root cause of this vulnerability is improper validation of user-supplied input within the IBM i Access Client Solutions emulator macro engine. Specifically, the 'RunProgram' action provided by the macro language allows for the execution of external commands on the host system. The application fails to properly sanitize or constrain the input arguments passed to the 'RunProgram' command, enabling a form of command injection.\nThe attack flow begins when an authenticated user introduces a maliciously crafted emulator macro file to the system. This file can be delivered through various channels, such as sharing a macro file with a target user or placing it in a location where the client application automatically parses it. When the IBM i Access Client Solutions emulator executes the macro, the parser processes the 'RunProgram' action.\nBecause the input validation is insufficient, the application does not prevent the injection of arbitrary arguments or additional command strings into the execution flow. When the macro engine invokes the system's command execution interface to run the specified program, it includes the attacker-supplied, malicious input. This triggers the execution of unintended commands with the privileges of the user running the emulator.\nThe affected component is the macro processing engine of IBM i Access Client Solutions. Vulnerable versions are identified as 1.1.2.0 through 1.1.9.15. The exploitation does not require administrative privileges, as the executed commands inherit the security context of the authenticated user. Network exposure is limited to the system where the client software is installed and executing, as the vulnerability is triggered locally through the interaction between the user, the client software, and the malicious macro file. Post-exploitation, an attacker can leverage this execution capability to run local system binaries, deploy additional scripts, or manipulate files and configurations accessible to the current user, effectively bypassing intended restrictions within the emulation session environment."
}
CVE-2026-14276: IBM i Access Macro Injection (MEDIUM Severity, CVSS: 6.3) | Sceawere