Executive brief
IBM i is a server operating system used to run mission-critical business applications. This vulnerability allows an authenticated remote attacker to bypass security restrictions through a flaw in how the multipart message parser interprets data, potentially allowing an attacker to circumvent intended access controls.
Technical details
The vulnerability is an interpretation conflict (CWE-436) in the multipart parser of IBM i. An authenticated remote attacker with high privileges can exploit the flaw by sending specially crafted multipart messages that are interpreted differently than intended, leading to a bypass of security restrictions. The attack requires network access, authentication, high privilege level, and challenging exploit conditions (AC:H). The impact is limited to integrity on a changed security scope, with no confidentiality or availability impact.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-12: disclosed