CVE-2026-16987
8.8IBM · i
IBM i is susceptible to an external control of file name or path vulnerability, which may allow an authenticated local attacker to manipulate file operations.
Executive summary
A vulnerability in IBM i allows an authenticated local attacker to leverage improper path control to achieve total system compromise.
Vulnerability
This vulnerability involves external control of file name or path (CWE-73). It requires the attacker to have local access and low-level privileges to successfully manipulate file paths, potentially leading to unauthorized file access or modification.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high severity risk. Successful exploitation could allow a malicious actor to bypass security controls, leading to total compromise of confidentiality, integrity, and availability of the affected IBM i system.
Remediation
Immediate Action: Apply the specific PTF updates provided by IBM for your release: 7.6 (SJ10846), 7.5 (SJ10847), 7.4 (SJ10852), or 7.3 (SJ10854).
Proactive Monitoring: Monitor system logs for unauthorized file access attempts or unexpected modifications to sensitive system configuration files.
Compensating Controls: Ensure strict adherence to the principle of least privilege by limiting local user access to only those functions required for their specific business roles.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The high CVSS score reflects the serious potential for total system compromise if the vulnerability is exploited. Administrators should prioritize the application of the listed PTF updates during the next maintenance window to eliminate this risk.