Sceawere

Vulnerability Detail

CVE-2026-14866UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Access Client Solutions Certificate Authority Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
2h ago
Vendor
IBM
Product
i Access Client Solutions
Attack Type
CWE-798 Use of Hard-coded Credentials
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-08-12T21:17:35.757Z",
  "pubdate": "2026-08-12T21:17:35.757Z",
  "executiveSummary": "IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 contain a vulnerability involving the injection of a rogue certificate authority.\nThe vulnerability stems from a publicly writeable truststore utilized by the affected software.\nThis flaw allows local threat actors with appropriate access to modify the truststore and introduce unauthorized or rogue certificate authorities.\nThe primary impact of this vulnerability includes potential compromise of cryptographic trust boundaries, man-in-the-middle attacks against secure communications, and potential interception or tampering of sensitive network traffic processed by the client application.\nExploitation requires the ability to write to the underlying truststore file path utilized by the product.\nThe risk implication is significant as it undermines the integrity of SSL/TLS certificate validation mechanisms, potentially leading to unauthorized data exposure or malicious code execution vectors via trusted channel abuse.",
  "technicalDetails": "The root cause of this vulnerability lies in insecure file permission assignments on the truststore component utilized by IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13.\nSpecifically, the truststore file or directory is configured with overly permissive access control lists (ACLs) that permit public write operations by unauthorized local users or processes.\nThe vulnerable component is the certificate validation and trust management subsystem of the client application, which relies on reading pre-configured truststore files to establish trusted cryptographic channels.\nAttack flow begins when a malicious actor with local system access identifies the publicly writeable truststore file.\nThe attacker leverages standard file system modification privileges to inject a rogue certificate authority (CA) certificate directly into the application's trusted root store.\nOnce the rogue CA is injected, any subsequent outbound TLS or SSL connections initiated by IBM i Access Client Solutions will evaluate the injected CA as a trusted root.\nWhen the application connects to servers or services, the attacker can execute man-in-the-middle (MitM) positioning to present fraudulent certificates signed by the injected rogue CA.\nThe application accepts the fraudulent certificate as valid due to the compromised truststore, allowing the attacker to intercept, decrypt, modify, or forge network traffic between the client and the target IBM i system.\nAuthentication and privilege requirements for initial exploitation are limited to local file system write access to the specific truststore path.\nNo remote network exposure is strictly required for the foundational file modification, although post-exploitation impact extends to compromised network communications and potential credential harvesting during active sessions."
}
CVE-2026-14866: IBM i Access Client Solutions Certificate Authority Injection (HIGH Severity, CVSS: 7.7) - Sceawere