Sceawere
Vulnerability Detail
CVE-2026-17197UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i Client-Asserted Identity Security Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- i
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-08-13T19:17:18.640Z",
"pubdate": "2026-08-13T19:17:18.640Z",
"executiveSummary": "A security restriction bypass vulnerability has been identified in IBM i versions 7.6, 7.5, 7.4, and 7.3.\nThe vulnerability arises due to improper validation of client-asserted identity within the affected operating system components.\nA remote attacker can exploit this flaw to bypass established security restrictions, potentially gaining unauthorized access or performing actions beyond their intended privilege level.\nThe risk implication is significant as it undermines the identity verification and access control mechanisms of the platform.\nExploitation requires network access and relies on the system's failure to properly authenticate or validate assertions provided by clients during connection or transaction handling.\nOrganizations utilizing the specified versions of IBM i should review applicable vendor advisories and apply available updates or workarounds to mitigate the risk of unauthorized access.",
"technicalDetails": "The root cause of the vulnerability stems from insufficient validation logic regarding client-asserted identities within the authentication and authorization subsystems of IBM i.\nWhen clients initiate communication or request services, the system relies on identifying attributes asserted by the client.\nDue to improper input validation and trust boundary enforcement, the affected component fails to cryptographically verify or adequately corroborate the authenticity of the claimed identity against trusted security authorities.\nAn unauthenticated or low-privileged remote attacker can craft malicious requests or manipulate connection parameters containing forged client-asserted identities.\nDuring the attack flow, the vulnerable service accepts the unverified identity assertion at face value, incorrectly mapping the request to a security context or user profile associated with the asserted identity.\nThis circumvents standard authentication controls and security restrictions, allowing the execution of operations or access to resources that should otherwise be denied.\nThe affected products include IBM i versions 7.6, 7.5, 7.4, and 7.3.\nThe vulnerability is exploitable remotely over the network without requiring complex preconditions, provided the target service processes client-asserted identities without strict validation.\nPost-exploitation impact includes unauthorized access to sensitive system resources, data exposure, and potential compromise of system integrity depending on the privileges associated with the spoofed identity."
}