Junglewise Threat Intelligence

CVE-2026-16941: IBM i improper authorization in system message modification

CVE-2026-16941 · Severity: medium · CVSS 4.3 · Published 2026-09-04

Executive brief

IBM i is an enterprise operating system used by large organizations for mission-critical business applications and data management. A vulnerability allows authenticated remote users to modify system messages due to weak authorization controls, potentially enabling them to inject malicious or misleading information into system operations. This could disrupt normal operations, compromise audit trails, or deceive system administrators about the true state of the system.

Technical details

The vulnerability is an incorrect authorization flaw (CWE-863) that permits a remote authenticated attacker to modify certain system messages. The issue stems from improper access control checks in the system message handling components. Attack requires network access and valid authentication credentials; no user interaction or elevated privileges are needed. An attacker can exploit this to alter system messages, potentially affecting operational visibility and audit logging. Patches are available for all affected versions: IBM i 7.6 (PTF SJ11201), 7.5 (PTF SJ11210), and 7.4 (PTF SJ11211).

Affected products

  • IBM IBM i 7.4, 7.5, 7.6

Timeline

  • 2026-09-04: disclosed
  • 2026-09-04: patched: Patches released for all affected versions (PTF SJ11201, SJ11210, SJ11211)

References

Related threats