CVE-2026-14866: IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.
Other sources
IBM i Access Client Solutions is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14866?
CVE-2026-14866 has a severity score of 7.7, classified as high.
How do I fix CVE-2026-14866?
To fix CVE-2026-14866, upgrade IBM i Access Client Solutions to a version that addresses the vulnerability.
What are the potential risks associated with CVE-2026-14866?
The primary risk of CVE-2026-14866 is the injection of rogue certificate authorities, compromising system security.
Which versions of IBM i Access Client Solutions are affected by CVE-2026-14866?
CVE-2026-14866 affects IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13.
Can CVE-2026-14866 lead to data breaches?
Yes, CVE-2026-14866 can potentially lead to data breaches by allowing unauthorized access through rogue certificates.