Sceawere
Vulnerability Detail
CVE-2026-17075UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i Authentication Token Validation Flaw
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- i
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-08-13T21:17:41.390Z",
"pubdate": "2026-08-13T21:17:41.390Z",
"executiveSummary": "This vulnerability involves an authentication token validation defect affecting IBM i 7.6, 7.5, 7.4, and 7.3. The security flaw allows a remote threat actor to bypass standard security boundaries, resulting in the unauthorized acquisition of sensitive information and the execution of unauthorized administrative or system operations.\nThe core issue stems from improper validation mechanisms governing authentication tokens used within the affected operating system versions. This cryptographic or logical validation failure permits malicious actors to supply crafted or manipulated tokens that are incorrectly trusted by the system.\nRisk implications are severe, as successful exploitation undermines the confidentiality, integrity, and availability of the underlying operating environment. The attacker capabilities include unauthorized data access and command execution without requiring prior valid credentials, assuming network reachability to the vulnerable service endpoints.\nNo specific preconditions or complex interaction requirements are explicitly detailed beyond remote network access, emphasizing the necessity for prompt administrative action to secure affected systems against potential exploitation attempts.",
"technicalDetails": "The vulnerability resides within the authentication and session management subsystems of IBM i 7.6, 7.5, 7.4, and 7.3, specifically involving how the system processes and verifies authentication tokens.\nThe root cause is attributable to improper validation of authentication tokens, a flaw where the software fails to adequately verify the authenticity, integrity, structural correctness, or cryptographic signature of tokens presented during connection or request initiation.\nThe attack flow begins when a remote unauthenticated attacker crafts a malicious payload containing an invalid, expired, or improperly structured authentication token designed to exploit the parsing or verification logic of the vulnerable component.\nUpon transmission over the network to the target IBM i instance, the vulnerable component processes the token without enforcing rigorous validation checks. Because the security checks are bypassed or incorrectly implemented, the system erroneously associates the malicious request with an authorized session or elevated security context.\nNetwork exposure is a critical factor, as the vulnerability is remotely exploitable, allowing threat actors across the network perimeter to interact with vulnerable services handling authentication token verification.\nAuthentication and privilege requirements are fundamentally subverted by the flaw; the attacker does not need to possess valid credentials or prior privileges to initiate the attack sequence, effectively leveraging the validation bypass to assume unauthorized capabilities.\nThe resulting post-exploitation impact includes the unauthorized disclosure of sensitive system information, configuration data, or user credentials, alongside the execution of unauthorized operations that can compromise system stability, data integrity, and operational security."
}