Sceawere
Vulnerability Detail
CVE-2026-16941UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i Improper Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- IBM
- Product
- i
- Attack Type
- CWE-863 Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-04T17:16:52.770Z",
"pubdate": "2026-09-04T17:16:52.770Z",
"executiveSummary": "IBM i 7.4, 7.5, and 7.6 are susceptible to an improper authorization vulnerability that allows a remote authenticated attacker to modify specific system messages. This security flaw stems from insufficient access controls over internal message handling mechanisms. By exploiting this vulnerability, an attacker with valid system credentials can manipulate system-generated notifications, potentially misleading system administrators or users. The risk implication involves the compromise of system integrity and the potential for social engineering or the obfuscation of malicious activities through the alteration of audit trails or system logs. The vulnerability requires the attacker to have pre-existing authenticated access to the IBM i environment to execute the unauthorized modifications.",
"technicalDetails": "The vulnerability originates from an improper authorization check within the system messaging subsystem of IBM i versions 7.4, 7.5, and 7.6. Specifically, the system fails to adequately validate the permissions of an authenticated user when attempting to modify existing system messages or inject new entries into system-level message queues. Under normal operational constraints, the modification of system-wide messages is restricted to high-privileged service accounts or administrative profiles to ensure the integrity of system communication and audit telemetry.\nThe attack flow requires the adversary to first obtain authenticated access to the target IBM i system. Upon achieving an authenticated session, the attacker interacts with the system interfaces responsible for managing or displaying system messages—such as message queues or program message queues. By leveraging the insufficient authorization oversight, the attacker can transmit requests to the underlying APIs or command interfaces that handle these messages. Because the system does not enforce strict Access Control Lists (ACLs) or privilege verification for these specific operations, the request is processed, allowing the attacker to overwrite or tamper with system notifications.\nThis unauthorized modification can be used to perform several malicious post-exploitation actions. For example, an attacker could suppress legitimate system warnings regarding unauthorized access, escalate their footprint by spoofing legitimate administrator communications, or insert deceptive messages that trick operators into performing actions that further weaken system security. Because system messages are often relied upon for monitoring system health and identifying potential threats, the ability to alter these messages effectively undermines the system's logging and alerting capabilities, making detection of subsequent exploitation attempts significantly more difficult. The vulnerability does not require physical access and can be exercised over a network connection, provided the attacker maintains valid authenticated credentials."
}