Junglewise Threat Intelligence

CVE-2026-16695: IBM i Access Client Solutions OS command injection

CVE-2026-16695 · Severity: high · CVSS 7.8 · Published 2026-08-12

Technologies: IBM i Access Client Solutions. Vendors: IBM.

Executive brief

IBM i Access Client Solutions is a client application used to connect to and manage IBM i systems. A local attacker can execute arbitrary code by exploiting improper sanitization of user input in OS commands, potentially compromising the workstation and accessing sensitive business systems. This requires local access and user interaction but can result in complete system compromise.

Technical details

The vulnerability is an OS command injection flaw (CWE-78) in IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13, arising from improper neutralization of special elements in OS commands. Attack vector is local with no privilege requirement, but user interaction is required to trigger the exploit. An attacker with local access can inject malicious commands that will be executed with the privileges of the user running the application. The vulnerability is fixed in version 1.1.9.14 and later.

Affected products

  • IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13

Timeline

  • 2026-08-12: disclosed: CVE-2026-16695 published
  • 2026-08-12: patched: Fixed in version 1.1.9.14 and later

References

Related threats