CVE-2026-16674
8.8IBM · i
IBM i is affected by an untrusted search path vulnerability, which could allow an authenticated user to achieve arbitrary code execution via manipulated search paths.
Executive summary
An untrusted search path vulnerability in IBM i allows an authenticated attacker to execute arbitrary code with high system impact.
Vulnerability
This vulnerability relates to an untrusted search path (CWE-426) within the system, specifically affecting 5770-SS1 Option 3. An authenticated attacker can influence the search path to load malicious binaries instead of intended system files.
Business impact
The CVSS score of 8.8 confirms the critical nature of this flaw. By exploiting this path manipulation, an attacker can gain the same privileges as the application, leading to complete system compromise, data theft, or unauthorized modification of system resources.
Remediation
Immediate Action: Deploy the applicable PTF updates for 5770-SS1 Option 3, specifically SJ10874 or SJ11023 for 7.6, SJ10875 or SJ11024 for 7.5, and SJ10876 or SJ11025 for 7.4.
Proactive Monitoring: Monitor system logs for changes to environment variables or unexpected execution of binaries from non-standard locations.
Compensating Controls: Utilize file integrity monitoring to detect unauthorized additions or modifications to system path directories.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a clear path to full system compromise for authenticated users. Organizations should verify their current patch level and apply the recommended IBM fixes immediately to reduce the attack surface.