CVE-2026-16906
8.8IBM · i
IBM i 7 contains an OS command injection vulnerability, allowing an authenticated attacker to execute arbitrary system commands.
Executive summary
An OS command injection vulnerability in IBM i 7.5 and 7.6 allows an authenticated attacker to achieve total system compromise.
Vulnerability
This vulnerability is caused by improper neutralization of special elements used in an OS command (CWE-78). An authenticated attacker with low privileges can leverage this flaw to execute arbitrary commands on the underlying operating system.
Business impact
The CVSS score of 8.8 reflects the high potential for total system compromise, including unauthorized data access, modification, and service disruption. Because this allows for arbitrary command execution, an attacker could escalate their control over the IBM i environment, leading to significant operational downtime and potential loss of sensitive business data.
Remediation
Immediate Action: Apply the relevant Program Temporary Fix (PTF) for your release: SJ10931 for version 7.6, or SJ11010 for version 7.5.
Proactive Monitoring: Review system access logs for unusual command execution patterns or unauthorized attempts to access system-level utilities.
Compensating Controls: Restrict user permissions to the absolute minimum required for job functions to limit the potential blast radius of an authenticated account compromise.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the high CVSS score and the nature of command injection flaws, administrators must prioritize the application of the specified PTFs. Ensure that all systems running IBM i 7.5 or 7.6 are patched during the next available maintenance window to mitigate the risk of unauthorized system-level access.