Junglewise Threat Intelligence

CVE-2026-17262: IBM i FTP authentication denial of service

CVE-2026-17262 · Severity: medium · CVSS 5.4 · Published 2026-09-18

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is a business-critical operating system that runs on enterprise servers. An improper validation flaw in the FTP (File Transfer Protocol) service allows local attackers to cause denial of service by sending specially crafted FTP authentication commands, potentially disrupting file transfer operations and system availability.

Technical details

A CWE-78 OS command injection vulnerability in IBM i's FTP implementation fails to properly validate authentication commands, allowing local attackers to trigger a denial of service condition. The vulnerability requires local access (adjacent network vector per CVSS vector AV:A) and no authentication, resulting in integrity and availability impact. Patches are available as PTFs for all affected versions.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-09-18: disclosed: IBM security bulletin published
  • 2026-09-18: patched: PTFs released for versions 7.3 (SJ11384), 7.4 (SJ11383), 7.5 (SJ11382), 7.6 (SJ11371)

References

Related threats