Junglewise Threat Intelligence

CVE-2026-17045: IBM i session management authentication bypass

CVE-2026-17045 · Severity: high · CVSS 8.1 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise operating system used to run mission-critical business applications and databases. A flaw in its session management allows authenticated attackers to bypass authentication controls, perform unauthorized operations, and access sensitive information without proper authorization. This could compromise the confidentiality and integrity of business data and systems.

Technical details

CVE-2026-17045 is an authentication bypass vulnerability in IBM i's Digital Certificate Manager (DCM) stemming from improper session management. The vulnerability is classified as CWE-294 (Authentication Bypass by Capture-replay), allowing an authenticated attacker to replay or manipulate session tokens to gain unauthorized access. Attack requires network connectivity and valid credentials (low privilege sufficient), with no user interaction needed. A successful exploit enables an attacker to perform privileged operations and access sensitive information. IBM has released PTF patches (SJ10907 for 7.6, SJ10906 for 7.5, SJ10905 for 7.4, SJ10904 for 7.3) to address this flaw.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-12: disclosed
  • 2026-08-12: patched: PTF patches released for all affected versions

References

Related threats