Sceawere
Vulnerability Detail
CVE-2026-17438UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i Privilege Management Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.4
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- i
- Attack Type
- CWE-269 Improper Privilege Management
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper privilege management.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.4",
"pubDate": "2026-08-13T21:17:42.810Z",
"pubdate": "2026-08-13T21:17:42.810Z",
"executiveSummary": "A privilege management vulnerability exists in IBM i versions 7.3, 7.4, 7.5, and 7.6 that could allow a local attacker to obtain sensitive information or modify data. The vulnerability arises from improper handling of privilege boundaries within the operating system architecture, leading to unauthorized access states.\nThe primary impact of successful exploitation includes confidentiality breaches via sensitive information disclosure and integrity compromises through unauthorized data modification. Affected systems encompass IBM i deployments running the specified legacy and current OS versions.\nExploitation of this vulnerability requires local access to the target system. An attacker must possess local privileges to interact with the vulnerable subsystem or component, leveraging the flawed privilege management logic to escalate capabilities or perform operations outside their intended authorization scope.\nThe risk implication is significant within multi-tenant or shared environments where strict privilege separation is required to prevent unauthorized data access and tampering. Remediation relies on applying vendor-supplied security fixes and adhering to principle-of-least-privilege hardening practices to limit local attack surfaces.",
"technicalDetails": "The vulnerability is rooted in improper privilege management logic implemented within IBM i 7.3, 7.4, 7.5, and 7.6. Specifically, the affected component fails to adequately enforce authorization checks or correctly manage security contexts during specific local operations, allowing processes or users to bypass intended security controls.\nThe attack vector is strictly local, requiring the threat actor to have initial authenticated access to the target IBM i environment. Network exposure is not a direct requirement for this vector, as the flaw resides within local OS-level privilege boundaries rather than remote network services.\nThe attack flow typically proceeds in the following sequence: First, the local attacker establishes a session on the IBM i system with standard user privileges. Second, the attacker identifies and interacts with the vulnerable OS component or utility that suffers from improper privilege management. Third, by supplying specifically crafted inputs or executing designated system commands within the context of the flaw, the attacker forces the component to perform operations or grant access surpassing the user's assigned authorization level.\nPost-exploitation impact allows the attacker to read restricted files, system data, or memory structures, resulting in sensitive information disclosure. Furthermore, the ability to modify data can lead to unauthorized alterations of system configurations, application data, or critical records, undermining the integrity of the operating system environment.\nAuthentication is required to the extent that the actor must be a local system user; however, the privilege requirement is low, as unprivileged or standard local users can potentially trigger the improper privilege management condition to execute unauthorized actions. The vulnerable components are integral parts of the IBM i operating system architecture across versions 7.3, 7.4, 7.5, and 7.6."
}