CVE-2026-16860

9.9

IBM · i

IBM i versions 7.3 through 7.6 contain an uncontrolled search path element vulnerability that allows authenticated attackers to execute arbitrary code.

Executive summary

An authenticated remote attacker can exploit an uncontrolled search path element in IBM i to execute arbitrary code, compromising the security of the operating system.

Vulnerability

The software does not securely validate the search path for executable components. An authenticated attacker can leverage this to force the system to load malicious code, resulting in arbitrary code execution with elevated privileges.

Business impact

While this vulnerability requires prior authentication, the potential for arbitrary code execution creates a significant risk for lateral movement and privilege escalation within the organization. With a CVSS score of 9.9, the impact to system integrity is severe, as it allows an attacker to bypass security controls and maintain persistent access to the IBM i environment.

Remediation

Immediate Action: Apply the specific Program Temporary Fix (PTF) for your version: 7.6 (SJ10879), 7.5 (SJ10880), 7.4 (SJ10881), or 7.3 (SJ10882).

Proactive Monitoring: Review user account activities and audit logs for unauthorized changes to system configurations or the execution of unauthorized binaries.

Compensating Controls: Enforce strict access control policies and regularly audit user permissions to ensure that even if an account is compromised, the attacker's ability to perform malicious actions is limited.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

IBM i administrators must treat this vulnerability as a high-priority item. Apply the provided PTFs as soon as possible to prevent authenticated users from escalating privileges or executing arbitrary code that could jeopardize the entire system.

More IBM CVEs