CVE-2026-14275: IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.16
Event History
Frequently Asked Questions
Which releases are identified as affected?
The affected range is IBM i Access Family 1.1.2.0 through 1.1.9.15. Organizations should compare their deployed release against this range.
What does an attacker need to exploit this issue?
Exploitation requires authentication with low privileges and does not require user interaction. The CVSS vector indicates network attack access and low attack complexity.
What level of access could successful exploitation provide?
A successful attacker could execute arbitrary commands with the privileges of a normal user on the system. The reported impact includes limited effects on confidentiality, integrity, and availability.