Executive brief
IBM i is a commercial operating system used to manage critical business applications and data. This vulnerability allows authenticated remote attackers to bypass path validation controls and access sensitive information they should not be able to read. The flaw could lead to unauthorized exposure of confidential business data, system files, or user credentials.
Technical details
This vulnerability stems from improper validation of user-supplied path input in IBM i, allowing path traversal attacks. An authenticated attacker can craft malicious path requests to bypass pathname restrictions and access files outside the intended directory. The vulnerability requires authentication and network access but does not require user interaction. Successful exploitation results in unauthorized information disclosure. IBM recommends applying the available security patches to affected versions.
Affected products
- IBM IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-12: disclosed