Executive brief
IBM i is an enterprise server operating system used by organizations to run critical business applications. This vulnerability allows an attacker to bypass WebSocket origin validation and obtain sensitive information through cross-origin WebSocket connections without requiring authentication. An attacker could intercept or exfiltrate data transmitted over WebSockets by spoofing the origin header.
Technical details
The vulnerability is a missing origin validation flaw (CWE-1385) in the WebSocket implementation of IBM i versions 7.3 through 7.6. The affected component improperly validates the origin header during WebSocket handshake, allowing a remote attacker without authentication to establish unauthorized WebSocket connections and access sensitive information. The attack requires user interaction (UI:R) and is network-accessible (AV:N). IBM has released PTF patches (SJ11196, SJ11197, SJ11200, SJ11187 for 7.6, 7.5, 7.4, 7.3 respectively under Option 3, and SJ11377, SJ11376, SJ11375, SJ11374 under Option 34) to remediate this issue.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: PTF patches available for all affected versions