Junglewise Threat Intelligence

CVE-2026-17057: IBM i missing authentication in NFS

CVE-2026-17057 · Severity: medium · CVSS 6.5 · Published 2026-09-04

Executive brief

IBM i is an enterprise operating system used to run mission-critical business applications and databases. A vulnerability in its Network File System (NFS) component allows remote attackers to bypass authentication protections, potentially causing service outages and corrupting data without needing valid credentials or user interaction.

Technical details

CVE-2026-17057 is a missing authentication vulnerability (CWE-306) in IBM i's Network File System (NFS) that allows remote attackers to perform critical operations without proper authorization. The vulnerability is reachable over the network with no authentication required and no user interaction necessary. An attacker can exploit this to cause denial of service (availability impact) and modify data (integrity impact). Patches are available via PTF releases for IBM i versions 7.3, 7.4, 7.5, and 7.6.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-09-04: disclosed
  • 2026-09-04: patched: PTF releases available for all affected versions (7.3, 7.4, 7.5, 7.6)

References

Related threats