CVE-2026-14277: IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file.
Other sources
IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.16
Event History
Frequently Asked Questions
Which deployments are affected?
IBM i Access Family versions 1.1.2.0 through 1.1.9.15 are identified as affected.
What level of access does an attacker need?
An attacker must be authenticated. The issue allows command execution with normal user privileges, not elevated privileges.
What is required to exploit the issue?
Exploitation involves improper validation of user-supplied input in a session file. The provided data does not identify any user-interaction requirement.