Sceawere

Vulnerability Detail

CVE-2026-17088UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Path Traversal Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-13T21:17:41.900Z",
  "pubdate": "2026-08-13T21:17:41.900Z",
  "executiveSummary": "A path traversal vulnerability has been identified in IBM i versions 7.6, 7.5, 7.4, and 7.3, posing significant security risks to enterprise environments.\nThe vulnerability allows a remote authenticated attacker to bypass intended directory restrictions and obtain sensitive information that should otherwise be restricted.\nThe security flaw stems from improper input validation within the affected software component, enabling malicious actors to supply specially crafted file paths containing traversal sequences.\nSuccessful exploitation of this vulnerability requires the attacker to possess valid authentication credentials to the target system.\nThe primary impact of this flaw is the unauthorized disclosure of confidential data, which could facilitate subsequent attacks or compromise overall system confidentiality.\nOrganizations utilizing the affected IBM i versions must address this exposure promptly to maintain data integrity and prevent unauthorized information retrieval.",
  "technicalDetails": "The vulnerability is a path traversal flaw residing within IBM i 7.6, 7.5, 7.4, and 7.3.\nThe root cause of the issue is the insufficient sanitization and validation of user-supplied input utilized in file system operations.\nWhen processing requests, the vulnerable component fails to properly neutralize directory traversal sequences, such as dot-dot-slash (../) patterns, allowing navigation outside the designated root directory.\nTo exploit this vulnerability, a remote authenticated attacker interacts with the vulnerable service or application interface.\nThe attack flow begins when the adversary crafts a malicious HTTP request or protocol interaction containing directory traversal directives targeting sensitive system files or restricted directories.\nUpon receipt, the application processes the tainted input without adequately restricting the file path boundaries, leading to the retrieval of the targeted files from the underlying operating system file system.\nThe payload behavior involves traversing the directory structure to access unauthorized file paths, subsequently returning the contents of those files within the response to the attacker.\nExploitation requirements dictate that the attacker must have network access to the vulnerable service and possess valid authentication credentials to interact with the authenticated interfaces.\nThe post-exploitation impact includes the unauthorized disclosure of sensitive information, such as configuration files, system data, or other restricted content accessible under the privileges of the executing process.\nNo specific privilege requirements beyond standard remote authentication are explicitly detailed, though the scope of accessible files is inherently bound to the access rights of the underlying service process."
}
CVE-2026-17088: IBM i Path Traversal Vulnerability (MEDIUM Severity, CVSS: 4.3) - Sceawere