CVE-2026-13105

8.8

IBM · i Access Client Solutions

IBM i Access Client Solutions contains a path traversal vulnerability that allows attackers to access restricted directories on the host system.

Executive summary

A path traversal vulnerability in IBM i Access Client Solutions exposes the system to unauthorized file access and potential system compromise.

Vulnerability

This is a path traversal vulnerability (CWE-22) that allows an unauthenticated, remote attacker to read or potentially write files outside of the intended directory structure. The vulnerability requires user interaction to facilitate the attack.

Business impact

Successful exploitation allows an attacker to bypass directory restrictions, potentially leading to unauthorized data disclosure or the modification of sensitive system files. Given the CVSS score of 8.8, this vulnerability poses a significant risk to the confidentiality, integrity, and availability of the affected environment.

Remediation

Immediate Action: Upgrade to IBM i Access Client Solutions version 1.1.9.14 or later to apply the necessary security patch.

Proactive Monitoring: Review system access logs for unusual path strings, such as sequences like dot-dot-slash (../), which are indicative of path traversal attempts.

Compensating Controls: Ensure the application is running with the minimum necessary system privileges to limit the impact of a potential directory traversal breakout.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The high severity of this vulnerability necessitates immediate attention to prevent potential system compromise. Administrators should prioritize upgrading to version 1.1.9.14 across all deployments to fully remediate the underlying path traversal risk.

More IBM CVEs