Sceawere

Vulnerability Detail

CVE-2026-16941UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Improper Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
4h ago
Vendor
IBM
Product
i
Attack Type
CWE-863 Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-04T17:16:52.770Z",
  "pubdate": "2026-09-04T17:16:52.770Z",
  "executiveSummary": "IBM i 7.4, 7.5, and 7.6 are susceptible to an improper authorization vulnerability that allows a remote authenticated attacker to modify specific system messages. This security flaw stems from insufficient access controls over internal message handling mechanisms. By exploiting this vulnerability, an attacker with valid system credentials can manipulate system-generated notifications, potentially misleading system administrators or users. The risk implication involves the compromise of system integrity and the potential for social engineering or the obfuscation of malicious activities through the alteration of audit trails or system logs. The vulnerability requires the attacker to have pre-existing authenticated access to the IBM i environment to execute the unauthorized modifications.",
  "technicalDetails": "The vulnerability originates from an improper authorization check within the system messaging subsystem of IBM i versions 7.4, 7.5, and 7.6. Specifically, the system fails to adequately validate the permissions of an authenticated user when attempting to modify existing system messages or inject new entries into system-level message queues. Under normal operational constraints, the modification of system-wide messages is restricted to high-privileged service accounts or administrative profiles to ensure the integrity of system communication and audit telemetry.\nThe attack flow requires the adversary to first obtain authenticated access to the target IBM i system. Upon achieving an authenticated session, the attacker interacts with the system interfaces responsible for managing or displaying system messages—such as message queues or program message queues. By leveraging the insufficient authorization oversight, the attacker can transmit requests to the underlying APIs or command interfaces that handle these messages. Because the system does not enforce strict Access Control Lists (ACLs) or privilege verification for these specific operations, the request is processed, allowing the attacker to overwrite or tamper with system notifications.\nThis unauthorized modification can be used to perform several malicious post-exploitation actions. For example, an attacker could suppress legitimate system warnings regarding unauthorized access, escalate their footprint by spoofing legitimate administrator communications, or insert deceptive messages that trick operators into performing actions that further weaken system security. Because system messages are often relied upon for monitoring system health and identifying potential threats, the ability to alter these messages effectively undermines the system's logging and alerting capabilities, making detection of subsequent exploitation attempts significantly more difficult. The vulnerability does not require physical access and can be exercised over a network connection, provided the attacker maintains valid authenticated credentials."
}
CVE-2026-16941: IBM i Improper Authorization Vulnerability (MEDIUM Severity, CVSS: 4.3) - Sceawere