Sceawere

Vulnerability Detail

CVE-2026-16867UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i NTLM Authentication Flaw

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
IBM
Product
i
Attack Type
CWE-287 Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-13T20:17:15.723Z",
  "pubdate": "2026-08-13T20:17:15.723Z",
  "executiveSummary": "An improper authentication vulnerability exists in IBM i 7.6, 7.5, 7.4, and 7.3 during NTLM session negotiation. This security flaw allows a remote attacker to interact with and access server resources under the authorization context of an authenticated user.\nThe vulnerability introduces significant risk to enterprise environments by breaking trust boundaries within network authentication protocols. An unauthorized remote actor leveraging this flaw can bypass standard session validation controls, leading to unauthorized resource access.\nThe attack vector involves network-based exploitation during the cryptographic handshake phase of NTLM session establishment. Successful exploitation requires network connectivity to the vulnerable IBM i server and relies on vulnerabilities within the session negotiation logic, without necessitating prior authentication by the threat actor.\nOrganizations utilizing affected IBM i versions face potential confidentiality and integrity risks as unauthorized entities gain the capability to query and interact with sensitive system resources using legitimate user privileges.",
  "technicalDetails": "The vulnerability resides within the authentication subsystem of IBM i 7.6, 7.5, 7.4, and 7.3, specifically during the handling and processing of NTLM session negotiation sequences.\nThe root cause stems from improper validation and verification of cryptographic exchanges and state maintenance during the NTLM challenge-response mechanism. Insufficient checks allow an attacker to improperly manipulate or bypass the authentication state machine, tricking the server into accepting an unauthorized session as valid.\nFrom a network exposure perspective, the vulnerable component is accessible remotely over protocols that utilize NTLM authentication services provided by the operating system. Attackers do not require prior privileges or pre-existing credentials on the target system to initiate the attack flow.\nThe step-by-step exploitation method involves the attacker intercepting or directly initiating a network connection with the IBM i server to negotiate an NTLM authentication session. During the negotiation phase, the attacker exploits the flawed session handling logic by supplying crafted or manipulated NTLM protocol messages.\nBecause the server fails to properly enforce strict cryptographic verification or state continuity during the handshake, it incorrectly associates the attacker's connection with the security context of a legitimately authenticated user.\nOnce the flawed negotiation succeeds, the server grants the malicious session the privileges and access rights of the targeted authenticated user. This post-exploitation state enables the remote attacker to execute authorized operations, read restricted server resources, and perform transactions within the scope of the hijacked security context.\nThe technical impact includes unauthorized authorization reuse, complete session spoofing capabilities during negotiation, and degradation of trust models dependent on NTLM on the specified IBM i releases."
}
CVE-2026-16867: IBM i NTLM Authentication Flaw (HIGH Severity, CVSS: 8.1) - Sceawere