Executive brief
IBM i is an enterprise operating system used to run critical business applications. A flaw in how the Debug Server component generates random values allows authenticated attackers to predict security tokens and bypass security controls, potentially gaining unauthorized access to sensitive data or functions.
Technical details
CVE-2026-17274 is a cryptographic weakness (CWE-330: Use of Insufficiently Random Values) in IBM i's Debug Server that uses predictable random number generation for security tokens. The vulnerability requires network access and valid authentication credentials. An authenticated remote attacker can predict the server-generated seeds, bypass security restrictions, and achieve confidentiality and integrity impacts. IBM has released PTF patches (SJ11305, SJ11306, SJ11307, SJ11308) for affected versions 7.6, 7.5, 7.4, and 7.3 respectively.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-04: disclosed
- 2026-08-31: patched: PTF patches released for all affected versions