Executive brief
IBM i is an enterprise operating system used to run business-critical applications and databases. The Network Authentication Service component improperly validates authentication during service-name matching, allowing an authenticated attacker to bypass security restrictions and gain unauthorized access to resources. This could lead to data exposure or unauthorized modifications to system data.
Technical details
The vulnerability exists in IBM i's Network Authentication Service (NAS) and is rooted in improper authentication validation during service-name matching (CWE-287). An attacker who is already authenticated to the system can exploit this flaw over the network without user interaction to bypass security controls. The vulnerability affects IBM i versions 7.3, 7.4, 7.5, and 7.6. IBM has published security patches in the form of PTFs (Program Temporary Fixes) for all affected versions: SJ11089 (7.6), SJ11090 (7.5), SJ11091 (7.4), and SJ11092 (7.3).
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-04: disclosed
- 2026-09-04: patched: PTF SJ11089 (7.6), SJ11090 (7.5), SJ11091 (7.4), SJ11092 (7.3)