Sceawere

Vulnerability Detail

CVE-2026-17226UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Out-of-Bounds Read Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-125 Out-of-bounds Read
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-08-13T21:17:42.557Z",
  "pubdate": "2026-08-13T21:17:42.557Z",
  "executiveSummary": "This vulnerability involves an out-of-bounds read flaw affecting IBM i versions 7.6, 7.5, 7.4, and 7.3. The security defect arises from improper bounds checking within internal memory management operations handled by the operating system.\nSuccessful exploitation of this vulnerability allows a remote authenticated attacker to read sensitive memory contents, potentially exposing confidential data, or to trigger a denial of service condition by causing application or system crashes due to memory access violations.\nThe risk implications include potential disclosure of critical system or user data residing in adjacent memory segments, alongside operational disruption from unexpected service terminations. The attack capability requires the adversary to possess valid authentication credentials to interact with vulnerable services on the target system.\nNo specific preconditions beyond authentication are explicitly detailed, but exploitation generally depends on the attacker's ability to supply maliciously crafted inputs or requests that trigger the out-of-bounds read condition within the vulnerable component of IBM i.",
  "technicalDetails": "The root cause of the vulnerability is an out-of-bounds read flaw residing in specific internal processing routines of IBM i versions 7.6, 7.5, 7.4, and 7.3. This memory safety issue occurs when the affected software reads data past the end allocation boundary of an intended buffer or memory structure.\nExploitation occurs when a remote authenticated attacker sends specially crafted requests or input data designed to manipulate internal offsets or length parameters processed by the vulnerable component. Because the application fails to adequately validate the boundaries of the input against allocated memory buffers, the read operation accesses unauthorized memory addresses adjacent to the legitimate buffer.\nThe attack flow proceeds as follows: First, the authenticated attacker establishes a network connection to the vulnerable service on the IBM i system. Second, the attacker transmits a crafted payload designed to interact with the vulnerable function. Third, the internal component processes the input and performs a memory read operation exceeding the allocated buffer limits. Fourth, the system either returns the unauthorized memory contents back to the attacker, resulting in sensitive information disclosure, or attempts to read unmapped memory regions, triggering a fatal segmentation fault and subsequent denial of service.\nThe vulnerability requires network exposure of the affected IBM i services and mandates that the attacker holds valid authentication credentials. Privilege requirements are limited to standard authenticated access levels. The payload behavior centers on triggering memory boundary violations rather than arbitrary code execution, manifesting primarily as data leakage or service crashes."
}
CVE-2026-17226: IBM i Out-of-Bounds Read Vulnerability (MEDIUM Severity, CVSS: 5.4) - Sceawere