Executive brief
IBM i is an enterprise operating system used to run critical business applications. A flaw in how the system manages thread-level security permissions allows a local attacker with basic user access to gain administrator-level privileges, potentially compromising the entire system and all data it contains. IBM has released security patches for all affected versions.
Technical details
The vulnerability is a privilege management flaw (CWE-269) in IBM i versions 7.3 through 7.6, where improper handling of thread authority swaps allows a local authenticated attacker to escalate privileges. The attack requires local access and low-level user privileges but no user interaction. An attacker can exploit this to gain elevated system privileges and compromise system integrity, confidentiality, and availability. IBM has released platform-specific PTFs (SJ10874, SJ10875, SJ10876, SJ10877 for versions 7.6, 7.5, 7.4, and 7.3 respectively) to remediate the issue.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-13: disclosed: CVE-2026-18101 published
- 2026-08-13: patched: PTFs released for IBM i 7.3–7.6