CVE-2026-13433: IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
IBM i Access Client Solutions (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.
Other sources
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13433?
The severity of CVE-2026-13433 is assessed as high with a score of 8.3.
How do I fix CVE-2026-13433?
To fix CVE-2026-13433, ensure you update IBM i Access Client Solutions to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2026-13433?
CVE-2026-13433 could allow a bad actor to run compromised code on the workstation of the ACS user.
Which versions of IBM i Access Client Solutions are affected by CVE-2026-13433?
IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 are affected by CVE-2026-13433.
How does CVE-2026-13433 allow unauthorized code execution?
CVE-2026-13433 allows unauthorized code execution by permitting the download of unverified product code from an IBM i environment.