Sceawere
Vulnerability Detail
CVE-2026-17445UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i User Profile Security Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- i
- Attack Type
- CWE-250 Execution with Unnecessary Privileges
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user profile name.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-08-12T20:17:40.410Z",
"pubdate": "2026-08-12T20:17:40.410Z",
"executiveSummary": "A security restriction bypass vulnerability has been identified in IBM i versions 7.6, 7.5, 7.4, and 7.3. This vulnerability stems from improper validation of an attacker-supplied user profile name within the operating system's security architecture.\nSuccessful exploitation of this flaw allows a remote authenticated attacker to bypass existing security restrictions, potentially leading to unauthorized access, privilege escalation, or unauthorized actions on the affected systems.\nThe vulnerability requires the attacker to possess authenticated access to the target environment, but leverages improper input sanitization and verification logic during the processing of user profile identifiers.\nGiven the core operating system nature of IBM i, the risk implications are severe, as compromising user profile validation mechanisms can undermine the system-wide access control framework and compromise the confidentiality, integrity, and availability of sensitive system resources.",
"technicalDetails": "The root cause of the vulnerability lies in the inadequate validation and sanitization of user profile names supplied by users during specific system operations or authentication-related routines.\nWhen an input containing a user profile name is processed by the affected IBM i subsystem, the underlying validation logic fails to rigorously verify the authenticity, format, or authorization boundaries associated with the supplied string.\nAffected products and versions include IBM i 7.6, 7.5, 7.4, and 7.3. The vulnerable component is responsible for parsing, verifying, and enforcing access boundaries based on user profile nomenclature within the operating system.\nExploitation requires the attacker to be authenticated to the target IBM i environment. Although remote access capabilities are noted, the attacker must already possess valid credentials or an established session that permits the submission of requests containing manipulated or crafted user profile names.\nThe attack flow proceeds as follows: First, the authenticated attacker crafts a malicious request or command containing an arbitrary, manipulated, or specifically formatted user profile name designed to deceive the validation routine. Second, the vulnerable component processes the input without performing sufficient boundary checks or cryptographic/system-level verification of the profile's validity or association with the session. Third, the improper validation logic accepts the supplied profile name as legitimate, bypassing the intended security controls. Finally, the attacker inherits or executes actions within the context of the improperly validated user profile, leading to unauthorized access or restriction bypass.\nPost-exploitation impact includes the potential circumvention of segregation of duties, unauthorized execution of privileged commands, or access to restricted data objects and system functions normally prohibited by the security profile of the authenticated attacker."
}