Sceawere

Vulnerability Detail

CVE-2026-17069UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i CSRF Security Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
4h ago
Vendor
IBM
Product
i
Attack Type
CWE-352 Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-13T20:17:18.303Z",
  "pubdate": "2026-08-13T20:17:18.303Z",
  "executiveSummary": "A security restriction bypass vulnerability has been identified in IBM i versions 7.6, 7.5, 7.4, and 7.3.\nThe vulnerability stems from improper validation of anti-Cross-Site Request Forgery (anti-CSRF) tokens within the affected systems.\nThis flaw allows a remote authenticated attacker to bypass intended security restrictions by tricking a victim into executing unauthorized actions against the web interface.\nThe primary impact involves the potential execution of unintended state-changing operations under the security context of the authenticated victim.\nExploitation requires the attacker to have network access and an authenticated victim interaction, typically through a malicious website or crafted link.\nThe risk implication centers on the loss of integrity for administrative or user actions performed within the IBM i environment, necessitating prompt remediation when patches are available from the vendor.",
  "technicalDetails": "The root cause of the vulnerability lies in the inadequate validation logic implemented for anti-Cross-Site Request Forgery (anti-CSRF) tokens across vulnerable components in IBM i 7.6, 7.5, 7.4, and 7.3.\nAnti-CSRF tokens are cryptographic or pseudo-random tokens designed to ensure that requests submitted to a web application are intentional and originate from the trusted user interface, rather than being forged by a third-party site.\nDue to improper validation, the application fails to adequately verify the presence, uniqueness, or validity of the anti-CSRF token upon receiving state-changing HTTP requests.\nAn attacker can exploit this weakness by constructing a malicious payload hosted on an external domain or injected via a separate vulnerability.\nWhen a remote authenticated user visits the malicious page while maintaining an active session with the vulnerable IBM i interface, the browser automatically includes session cookies and authentication credentials with cross-origin requests.\nBecause the validation mechanism incorrectly handles or completely omits strict verification of the anti-CSRF token, the IBM i server processes the forged request as a legitimate transaction initiated by the user.\nThe affected components are the web-based administrative and user interfaces associated with IBM i versions 7.6, 7.5, 7.4, and 7.3.\nThe attack vector is network-based and requires the attacker to successfully execute an interaction-based exploit against an authenticated session.\nPrivilege requirements on the attacker side are minimal in terms of direct system access, but the targeted victim must possess authenticated access to the IBM i web interface.\nPost-exploitation impact depends heavily on the privileges of the victim, potentially allowing the attacker to modify configurations, execute administrative tasks, or manipulate system resources within the scope of the user's permissions."
}
CVE-2026-17069: IBM i CSRF Security Bypass (HIGH Severity, CVSS: 8.1) - Sceawere