CVE-2026-14276: IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.16Patch SJ11504 - Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.16Patch SJ11505 - Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.16Patch SJ11506 - Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.16Patch SJ11507
Event History
Frequently Asked Questions
Which deployments are affected?
IBM i Access Family versions 1.1.2.0 through 1.1.9.15 are identified as affected. The issue is in IBM i Access Client Solutions emulator macros that use the RunProgram action.
What does an attacker need to exploit this issue?
An attacker needs to be authenticated and able to supply or use a malicious emulator macro containing a RunProgram action. No user interaction requirement is stated in the provided severity vector.
What access could exploitation provide?
Successful exploitation could allow arbitrary command execution with normal user privileges on the system. The reported impact includes low confidentiality, integrity, and availability impact.