Sceawere
Vulnerability Detail
CVE-2026-17099UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i Improper Authentication Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- i
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-08-13T21:17:42.033Z",
"pubdate": "2026-08-13T21:17:42.033Z",
"executiveSummary": "An improper authentication vulnerability exists within IBM i versions 7.6, 7.5, 7.4, and 7.3 that could potentially allow a remote attacker to obtain sensitive information.\nThis security flaw arises from insufficient verification of identity or improper handling of authentication credentials during communication sessions with the affected operating system.\nThe primary impact of this vulnerability is the unauthorized disclosure of confidential data, which compromises the confidentiality pillar of the targeted system.\nAffected products include IBM i 7.6, 7.5, 7.4, and 7.3, exposing organizations running these enterprise operating system versions to potential information leakage.\nThe risk implications are significant, as unauthorized extraction of sensitive information could facilitate further targeted attacks, internal privilege escalation, or compliance violations.\nAn attacker capable of exploiting this vulnerability operates remotely, leveraging the improper authentication controls to bypass intended security checks without necessarily possessing valid credentials.\nSuccessful exploitation requires network connectivity to vulnerable services exposed by the IBM i system, allowing unauthorized retrieval of sensitive data payloads directly from the affected components.",
"technicalDetails": "The root cause of this vulnerability lies in improper authentication mechanisms implemented within the affected IBM i environment.\nThe vulnerable components fail to adequately validate user identities or enforce strict cryptographic and logical authentication checks before granting access to protected data stores or communication channels.\nAffected software versions explicitly encompass IBM i 7.6, 7.5, 7.4, and 7.3.\nThe vulnerability is exposed over the network, allowing remote actors to interact directly with vulnerable listening services or application endpoints.\nAuthentication requirements are circumvented or improperly validated due to the flawed authentication logic, enabling unauthorized access without requiring standard, verified administrative or user credentials.\nPrivilege requirements for the attacking entity are minimal, as the improper authentication flaw itself grants the unauthorized access required to retrieve sensitive information.\nThe exploitation method involves crafting specialized network requests directed toward the vulnerable IBM i services.\nDuring the attack flow, the malicious actor initiates a connection to the target system and issues requests that bypass standard authentication flows due to the logic flaws in the identity verification routines.\nThe targeted service, failing to properly authenticate the session or requestor, processes the input and improperly returns sensitive system, user, or operational data within the response payload.\nThe payload behavior centers on the retrieval of confidential information rather than remote code execution or direct denial of service.\nPost-exploitation impact is characterized by the unauthorized exposure of sensitive information, which can include internal system configurations, operational data, or credentials that may assist the attacker in planning subsequent lateral movement or deeper system compromise within the network infrastructure."
}