Junglewise Threat Intelligence

CVE-2026-17206: IBM i buffer overflow in host servers

CVE-2026-17206 · Severity: high · CVSS 8.1 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise operating system that manages critical business applications and data. A buffer overflow vulnerability in its host server components could allow a remote attacker to execute arbitrary code, potentially compromising the entire system, exposing sensitive business data, or disrupting critical operations.

Technical details

CVE-2026-17206 is a buffer overflow vulnerability (CWE-787: Out-of-bounds Write) in IBM i host server components that allows unauthenticated remote attackers to execute arbitrary code. The vulnerability stems from improper validation of client-supplied data sent to host servers, which can be exploited by sending specially crafted malformed requests. Attack complexity is high, but no user interaction is required and the vulnerability is network-accessible. Successful exploitation grants full system compromise with confidentiality, integrity, and availability impact. IBM has released PTF patches (SJ11101/SJ11097 for 7.6, SJ11102/SJ11098 for 7.5, SJ11103/SJ11099 for 7.4, SJ11104/SJ11100 for 7.3) to remediate the issue.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed

References

Related threats