Junglewise Threat Intelligence

CVE-2026-14277: IBM i Access Family command injection via session file validation

CVE-2026-14277 · Severity: medium · CVSS 6.3 · Published 2026-09-14

Vendors: IBM.

Executive brief

IBM i Access Family is a suite of tools that allow authenticated users to connect to and manage IBM systems. A vulnerability in session file handling allows an authenticated user with legitimate access to inject and execute arbitrary operating system commands with standard user privileges, potentially compromising system integrity and enabling lateral movement within the environment.

Technical details

The vulnerability is a command injection flaw arising from improper validation of user-supplied input in a session file. An authenticated user can craft a malicious session file containing shell metacharacters or command sequences that are not properly sanitized before execution. The attack requires prior authentication and the ability to create or modify a session file, but does not require administrative privileges—the attacker gains the ability to execute commands only with their own user-level permissions. IBM has released fixes to address the input validation defect in affected versions.

Affected products

  • IBM i Access Family 1.1.2.0 through 1.1.9.15

Timeline

  • 2026-09-14: disclosed

References