Junglewise Threat Intelligence

CVE-2026-14276: IBM i Access Client Solutions command execution in emulator macro

CVE-2026-14276 · Severity: medium · CVSS 6.3 · Published 2026-09-14

Technologies: IBM i Access Client Solutions. Vendors: IBM.

Executive brief

IBM i Access Client Solutions is a terminal emulation and system access tool used by enterprises to connect to IBM i systems. An authenticated attacker can execute arbitrary commands with normal user privileges by crafting a malicious emulator macro with an improper RunProgram action, gaining the ability to run code on the target system.

Technical details

The vulnerability exists in the emulator macro RunProgram action handler, which fails to properly validate user-supplied input. An authenticated user can craft a malicious macro file that exploits this improper input validation to execute arbitrary operating system commands with the privileges of the user running the emulator. The attack requires the attacker to have authenticated access to the system and the ability to load a malicious macro file. The vulnerability allows code execution on the local or remote IBM i system being accessed.

Affected products

  • IBM i Access Client Solutions 1.1.2.0 through 1.1.9.15

Timeline

  • 2026-09-14: disclosed

References

Related threats