CVE-2026-13105: IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.
Other sources
IBM i Access Client Solutions is vulnerable to zip slip path traversal exploit when importing a configuration.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13105?
The severity of CVE-2026-13105 is rated high with a score of 8.8.
How do I fix CVE-2026-13105?
To mitigate CVE-2026-13105, users should update IBM i Access Client Solutions to the latest version that addresses the vulnerabilities.
What systems are affected by CVE-2026-13105?
CVE-2026-13105 affects IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13.
What type of exploit is associated with CVE-2026-13105?
CVE-2026-13105 is associated with a zip slip path traversal exploit during the configuration import process.
Is user interaction required for CVE-2026-13105 to be exploited?
Yes, user interaction is required as the exploit occurs when a user imports a configuration.