CVE-2026-16987

8.8

IBM · i

IBM i is susceptible to an external control of file name or path vulnerability, which may allow an authenticated local attacker to manipulate file operations.

Executive summary

A vulnerability in IBM i allows an authenticated local attacker to leverage improper path control to achieve total system compromise.

Vulnerability

This vulnerability involves external control of file name or path (CWE-73). It requires the attacker to have local access and low-level privileges to successfully manipulate file paths, potentially leading to unauthorized file access or modification.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high severity risk. Successful exploitation could allow a malicious actor to bypass security controls, leading to total compromise of confidentiality, integrity, and availability of the affected IBM i system.

Remediation

Immediate Action: Apply the specific PTF updates provided by IBM for your release: 7.6 (SJ10846), 7.5 (SJ10847), 7.4 (SJ10852), or 7.3 (SJ10854).

Proactive Monitoring: Monitor system logs for unauthorized file access attempts or unexpected modifications to sensitive system configuration files.

Compensating Controls: Ensure strict adherence to the principle of least privilege by limiting local user access to only those functions required for their specific business roles.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The high CVSS score reflects the serious potential for total system compromise if the vulnerability is exploited. Administrators should prioritize the application of the listed PTF updates during the next maintenance window to eliminate this risk.

More IBM CVEs