CVE-2026-13094: IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.
Other sources
IBM i Access Client Solutions is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13094?
CVE-2026-13094 has a high severity score of 7.8.
What impact does CVE-2026-13094 have on users?
CVE-2026-13094 allows for arbitrary code execution on Windows systems when IBM i Access Client Solutions is installed for all users.
How do I fix CVE-2026-13094?
To mitigate CVE-2026-13094, ensure the software is updated to a non-vulnerable version as specified by IBM.
Which versions are affected by CVE-2026-13094?
IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 are affected by CVE-2026-13094.
What type of vulnerability is CVE-2026-13094?
CVE-2026-13094 is classified as a code injection vulnerability.