Sceawere

Vulnerability Detail

CVE-2026-18669UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Activation Engine Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
1h ago
Vendor
IBM
Product
i
Attack Type
CWE-250 Execution with Unnecessary Privileges
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-12T18:17:28.723Z",
  "pubdate": "2026-08-12T18:17:28.723Z",
  "executiveSummary": "IBM i versions 7.6, 7.5, 7.4, and 7.3 contain a privilege escalation vulnerability resulting from a remote code execution flaw within the activation engine component.\nThe vulnerability allows an authenticated attacker to execute maliciously planted scripts with root authority, posing severe risks to system confidentiality, integrity, and availability.\nExploitation requires authentication and the ability to introduce a malicious script into the environment, after which the compromised activation engine processes execute the payload under the highest privilege level.\nThe implications of successful exploitation include total system compromise, unauthorized administrative access, and potential persistence mechanisms established across the affected IBM i operating system instances.",
  "technicalDetails": "The vulnerability resides within the activation engine component of IBM i, specifically affecting versions 7.6, 7.5, 7.4, and 7.3.\nThe root cause stems from insecure handling and execution of scripts by the activation engine, which fails to properly validate or sanitize execution inputs and contextual file paths during processing.\nThe attack flow requires an authenticated adversary to first place a maliciously crafted script within a location or mechanism accessible to the activation engine component.\nUpon triggering or during routine operational execution cycles of the activation engine, the vulnerable component processes the planted script.\nDue to improper authorization and execution contexts within the component, the script is executed with root authority rather than restricted privileges.\nNetwork exposure and authentication requirements dictate that the attacker must possess valid credentials to access the system and prepare the attack vector.\nThe payload behavior involves arbitrary command execution within the privileged context of the root user.\nThe post-exploitation impact includes complete administrative control over the operating system, allowing the adversary to modify system configurations, access sensitive data, disable security controls, or establish persistent unauthorized access across the enterprise environment."
}
CVE-2026-18669: IBM i Activation Engine Privilege Escalation (HIGH Severity, CVSS: 8.8) - Sceawere