Executive brief
IBM i Access Client Solutions (ACS), a tool used by administrators to manage IBM i systems, is vulnerable to remote code execution. If the software is configured to listen for requests from IBM i Navigator, an attacker could potentially take full control of the system. This could lead to unauthorized access to sensitive business data, service disruptions, or the deployment of malicious software.
Technical details
IBM i Access Client Solutions (ACS) versions 1.1.5.0 through 1.1.9.12 contain a remote code execution vulnerability classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component). The vulnerability is triggered when ACS is configured to listen for requests from IBM i Navigator. An authenticated attacker with low privileges can exploit this over the network to execute arbitrary code on the target system. The issue has been addressed in version 1.1.9.13, and IBM has also released Program Temporary Fixes (PTFs) for various IBM i releases (7.3 through 7.6).
Affected products
- IBM i Access Client Solutions (ACS) 1.1.5.0 - 1.1.9.12
Timeline
- 2026-05-27: advisory: Initial publication by IBM
- 2026-05-29: patched: Fixes available via Entitled Systems Support (ESS)
- 2026-06-01: disclosed: NVD publication date