Junglewise Threat Intelligence

CVE-2026-16693: IBM i cryptographic weakness in Digital Certificate Manager

CVE-2026-16693 · Severity: medium · CVSS 4.4 · Published 2026-09-04

Executive brief

IBM i is an enterprise server operating system used for mission-critical business applications. Digital Certificate Manager (DCM) is a component that handles encryption key management. A weakness in how DCM protects encryption keys using hardcoded constants allows authenticated attackers to recover sensitive key material, potentially leading to decryption of protected data and compromise of digital certificates.

Technical details

The vulnerability is a use of broken/risky cryptographic algorithms (CWE-327) where hardcoded cryptographic constants are used to obfuscate encryption keys in IBM i's Digital Certificate Manager. An authenticated attacker with high privileges on a local system can exploit this to obtain encryption keys that should remain protected. The attack vector is local rather than network-based, and requires elevated privileges (PR:H). No network component makes this exploitable remotely despite the "remote authenticated" phrasing in the summary. Patches have been released as program temporary fixes (PTFs) for all affected versions: 7.6 (SJ11156), 7.5 (SJ11159), 7.4 (SJ11158), and 7.3 (SJ11157).

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-09-04: disclosed
  • 2026-08-31: patched: PTFs released: 7.6 SJ11156, 7.5 SJ11159, 7.4 SJ11158, 7.3 SJ11157

References

Related threats