Junglewise Threat Intelligence

CVE-2026-17069: IBM i CSRF token validation bypass in Digital Certificate Manager

CVE-2026-17069 · Severity: high · CVSS 8.1 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i's Digital Certificate Manager (DCM) is a tool for managing digital certificates used in enterprise systems. A remote authenticated attacker can bypass security restrictions by exploiting improper validation of anti-CSRF tokens, potentially allowing unauthorized access to sensitive data and unauthorized operations on the system.

Technical details

The vulnerability is a Cross-Site Request Forgery (CSRF) bypass due to improper validation of anti-CSRF tokens in IBM i's Digital Certificate Manager. It requires authentication but no user interaction, and affects network-reachable services. An authenticated attacker can craft malicious requests to perform unauthorized operations and access sensitive information (CWE-352). Patches are available for IBM i 7.3, 7.4, 7.5, and 7.6 via PTF numbers SJ10904, SJ10905, SJ10906, and SJ10907 respectively.

Affected products

  • IBM IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed
  • 2026-08: patched: PTF SJ10907 (7.6), SJ10906 (7.5), SJ10905 (7.4), SJ10904 (7.3)

References

Related threats