Junglewise Threat Intelligence

CVE-2026-16987: IBM i LANG environment variable privilege escalation in PASE

CVE-2026-16987 · Severity: high · CVSS 8.8 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise server operating system used to run mission-critical business applications. A vulnerability in the Portable Application Solutions Environment (PASE) subsystem allows local users to manipulate the LANG environment variable to gain elevated system privileges. An attacker with local access could potentially bypass security controls and take unauthorized administrative actions on the system.

Technical details

The vulnerability exists in PASE (Portable Application Solutions Environment) due to improper validation of the LANG environment variable, classified as external control of file name or path (CWE-73). A local attacker with low privileges can exploit this by manipulating the LANG variable to escalate their access to higher privilege levels. The attack requires local system access and does not require user interaction. IBM has released PTFs (Program Temporary Fixes) for supported versions: 7.6 (SJ10846), 7.5 (SJ10847), 7.4 (SJ10852), and 7.3 (SJ10854).

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed
  • 2026-08-13: patched: PTF releases: 7.6 (SJ10846), 7.5 (SJ10847), 7.4 (SJ10852), 7.3 (SJ10854)

References

Related threats