Junglewise Threat Intelligence

CVE-2026-18527: IBM Application Runtime Expert for i privilege escalation

CVE-2026-18527 · Severity: critical · CVSS 9.9 · Published 2026-08-28

Vendors: IBM.

Executive brief

IBM Application Runtime Expert (ARE) for i is an administration tool used to manage applications and systems on IBM i servers. A remote vulnerability in the ARE GUI component allows an unauthenticated attacker to impersonate authenticated users and execute actions with their privileges, potentially compromising the entire IBM i system and any data or applications it hosts.

Technical details

The vulnerability is a privilege escalation flaw in the ARE GUI component that allows an unauthenticated remote attacker to execute actions under another user's authenticated profile. The vulnerability likely results from improper session management, authentication bypass, or insufficient authorization checks in the web interface. An attacker on the network can exploit this without valid credentials to gain elevated privileges on the IBM i system. Affected versions include IBM Administration Runtime Expert for i 1R1M0; organizations should check IBM support documentation for patch availability and workarounds.

Affected products

  • IBM Application Runtime Expert for i 1R1M0

Timeline

  • 2026-08-28: disclosed

References