Junglewise Threat Intelligence

CVE-2026-17203: IBM Administration Runtime Expert for i improper authentication

CVE-2026-17203 · Severity: high · CVSS 7.5 · Published 2026-08-28

Vendors: IBM.

Executive brief

IBM Administration Runtime Expert for i is a systems management tool used to administer IBM i servers. A remote authenticated attacker can exploit improper authentication enforcement to obtain sensitive information from the system without proper authorization checks. This could expose confidential data such as system configuration, credentials, or business-critical information stored on the server.

Technical details

The vulnerability is rooted in improper authentication enforcement (CWE-287) in IBM Administration Runtime Expert for i. A remote authenticated attacker can bypass authorization controls to access sensitive information on the system. The attack requires network access and no user interaction, making it easily exploitable by any authenticated user who gains access to the affected system. The vulnerability allows unauthorized information disclosure but does not permit modification or availability impact. IBM has released PTF SJ11185 to remediate the issue in version 1R1M0.

Affected products

  • IBM Administration Runtime Expert for i 1R1M0

Timeline

  • 2026-08-28: disclosed
  • 2026-08-21: patched: PTF SJ11185 released for version 1R1M0

References