Executive brief
IBM i is an enterprise server operating system used to run critical business applications and databases. An authenticated attacker can exploit unsafe reflection in the system to bypass security controls and gain unauthorized access to sensitive data and system functions. This vulnerability requires existing credentials but could allow an attacker to escalate privileges or access restricted information on affected servers.
Technical details
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes (CWE-915), allowing unsafe reflection in IBM i versions 7.3 through 7.6. An authenticated remote attacker can exploit this flaw to bypass security restrictions by manipulating object attributes at runtime. The attack requires valid authentication credentials and network access to the IBM i system. Successful exploitation allows an attacker to achieve high impact on confidentiality and integrity, with some availability impact. The vulnerability is present in Navigator for i and related components.
Affected products
- IBM IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-12: disclosed