Junglewise Threat Intelligence

CVE-2026-18101: IBM i privilege escalation in thread authority management

CVE-2026-18101 · Severity: high · CVSS 8.8 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise operating system used to run critical business applications. A flaw in how the system manages thread-level security permissions allows a local attacker with basic user access to gain administrator-level privileges, potentially compromising the entire system and all data it contains. IBM has released security patches for all affected versions.

Technical details

The vulnerability is a privilege management flaw (CWE-269) in IBM i versions 7.3 through 7.6, where improper handling of thread authority swaps allows a local authenticated attacker to escalate privileges. The attack requires local access and low-level user privileges but no user interaction. An attacker can exploit this to gain elevated system privileges and compromise system integrity, confidentiality, and availability. IBM has released platform-specific PTFs (SJ10874, SJ10875, SJ10876, SJ10877 for versions 7.6, 7.5, 7.4, and 7.3 respectively) to remediate the issue.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed: CVE-2026-18101 published
  • 2026-08-13: patched: PTFs released for IBM i 7.3–7.6

References

Related threats