Sceawere

Vulnerability Detail

CVE-2026-17057UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Missing Authentication Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
IBM
Product
i
Attack Type
CWE-306 Missing Authentication for Critical Function
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-04T17:16:52.893Z",
  "pubdate": "2026-09-04T17:16:52.893Z",
  "executiveSummary": "This vulnerability involves a critical flaw in IBM i 7.6, 7.5, 7.4, and 7.3 related to missing authentication for sensitive functions.\nThe absence of robust access controls allows remote, unauthenticated attackers to invoke critical system functions, leading to potential denial of service (DoS) and compromises to data integrity.\nBecause the vulnerability facilitates unauthorized command execution or state modification without valid credentials, the integrity of the IBM i environment is significantly threatened.\nRemote exploitation capabilities enable adversaries to interact with the target system over the network, bypassing expected authorization mechanisms.\nOrganizations operating affected IBM i versions face elevated risk, as the vulnerability does not require prior local system access or elevated user privileges to initiate, making it a high-priority exposure that necessitates immediate attention to prevent operational disruption and data corruption.",
  "technicalDetails": "The vulnerability resides in the core architectural handling of requests within the IBM i environment, specifically concerning the validation of authentication tokens or session state prior to executing privileged functions.\nThe root cause is identified as an improper implementation of access control checks (missing authentication) for critical function calls exposed to the network.\nAn unauthenticated remote attacker can exploit this flaw by sending specifically crafted requests to the vulnerable component that handles these functions. Because the system fails to verify the identity of the requester, it processes the request as if it originated from an authorized administrative or system-level source.\nThe attack flow proceeds as follows: 1) The attacker identifies the network-exposed interface or service that permits access to restricted functions. 2) The attacker transmits a request targeting a function that should be protected by authentication. 3) The target service, due to the identified security flaw, fails to enforce authentication protocols, effectively bypassing the gatekeeping mechanism. 4) The service proceeds to execute the requested logic with the context of a privileged user or system account.\nThe impact of this exploitation is two-fold: First, the attacker can cause a denial of service by triggering functions that consume excessive system resources, lock critical data structures, or cause the service process to crash or enter an unstable state. Second, the attacker may affect data integrity by performing unauthorized modifications to system data, configuration files, or user records through the illicit invocation of functions that manage these objects.\nThis vulnerability impacts IBM i versions 7.6, 7.5, 7.4, and 7.3. The lack of authentication requirements means that any entity with network access to the vulnerable IBM i service can potentially interact with these sensitive functions. No specific user privileges are required by the attacker at the time of exploitation because the system itself fails to perform the prerequisite check.\nPost-exploitation behavior depends heavily on the specific function invoked; however, the ability to alter system state without authorization fundamentally undermines the security model of the IBM i platform, requiring immediate remediation to restore system assurance."
}
CVE-2026-17057: IBM i Missing Authentication Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere