Executive brief
IBM i Access Family is a suite of tools that allow authenticated users to connect to and manage IBM systems. A vulnerability in session file handling allows an authenticated user with legitimate access to inject and execute arbitrary operating system commands with standard user privileges, potentially compromising system integrity and enabling lateral movement within the environment.
Technical details
The vulnerability is a command injection flaw arising from improper validation of user-supplied input in a session file. An authenticated user can craft a malicious session file containing shell metacharacters or command sequences that are not properly sanitized before execution. The attack requires prior authentication and the ability to create or modify a session file, but does not require administrative privileges—the attacker gains the ability to execute commands only with their own user-level permissions. IBM has released fixes to address the input validation defect in affected versions.
Affected products
- IBM i Access Family 1.1.2.0 through 1.1.9.15
Timeline
- 2026-09-14: disclosed