Sceawere
Vulnerability Detail
CVE-2026-18669UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i Activation Engine Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 1h ago
- Vendor
- IBM
- Product
- i
- Attack Type
- CWE-250 Execution with Unnecessary Privileges
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-12T18:17:28.723Z",
"pubdate": "2026-08-12T18:17:28.723Z",
"executiveSummary": "IBM i versions 7.6, 7.5, 7.4, and 7.3 contain a privilege escalation vulnerability resulting from a remote code execution flaw within the activation engine component.\nThe vulnerability allows an authenticated attacker to execute maliciously planted scripts with root authority, posing severe risks to system confidentiality, integrity, and availability.\nExploitation requires authentication and the ability to introduce a malicious script into the environment, after which the compromised activation engine processes execute the payload under the highest privilege level.\nThe implications of successful exploitation include total system compromise, unauthorized administrative access, and potential persistence mechanisms established across the affected IBM i operating system instances.",
"technicalDetails": "The vulnerability resides within the activation engine component of IBM i, specifically affecting versions 7.6, 7.5, 7.4, and 7.3.\nThe root cause stems from insecure handling and execution of scripts by the activation engine, which fails to properly validate or sanitize execution inputs and contextual file paths during processing.\nThe attack flow requires an authenticated adversary to first place a maliciously crafted script within a location or mechanism accessible to the activation engine component.\nUpon triggering or during routine operational execution cycles of the activation engine, the vulnerable component processes the planted script.\nDue to improper authorization and execution contexts within the component, the script is executed with root authority rather than restricted privileges.\nNetwork exposure and authentication requirements dictate that the attacker must possess valid credentials to access the system and prepare the attack vector.\nThe payload behavior involves arbitrary command execution within the privileged context of the root user.\nThe post-exploitation impact includes complete administrative control over the operating system, allowing the adversary to modify system configurations, access sensitive data, disable security controls, or establish persistent unauthorized access across the enterprise environment."
}