CVE-2026-16906

8.8

IBM · i

IBM i 7 contains an OS command injection vulnerability, allowing an authenticated attacker to execute arbitrary system commands.

Executive summary

An OS command injection vulnerability in IBM i 7.5 and 7.6 allows an authenticated attacker to achieve total system compromise.

Vulnerability

This vulnerability is caused by improper neutralization of special elements used in an OS command (CWE-78). An authenticated attacker with low privileges can leverage this flaw to execute arbitrary commands on the underlying operating system.

Business impact

The CVSS score of 8.8 reflects the high potential for total system compromise, including unauthorized data access, modification, and service disruption. Because this allows for arbitrary command execution, an attacker could escalate their control over the IBM i environment, leading to significant operational downtime and potential loss of sensitive business data.

Remediation

Immediate Action: Apply the relevant Program Temporary Fix (PTF) for your release: SJ10931 for version 7.6, or SJ11010 for version 7.5.

Proactive Monitoring: Review system access logs for unusual command execution patterns or unauthorized attempts to access system-level utilities.

Compensating Controls: Restrict user permissions to the absolute minimum required for job functions to limit the potential blast radius of an authenticated account compromise.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high CVSS score and the nature of command injection flaws, administrators must prioritize the application of the specified PTFs. Ensure that all systems running IBM i 7.5 or 7.6 are patched during the next available maintenance window to mitigate the risk of unauthorized system-level access.

More IBM CVEs