CVE-2026-14875: IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory.
Other sources
IBM i Access Client Solutions is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Access Client Solutions (ACS)to a version that resolves this vulnerability.Fixed in 1.1.9.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14875?
CVE-2026-14875 has a severity rating of 7.3 on the CVSS scale, which is classified as high.
How do I fix CVE-2026-14875?
To fix CVE-2026-14875, update IBM i Access Client Solutions to a version that addresses the vulnerability.
What are the risks associated with CVE-2026-14875?
CVE-2026-14875 poses a risk of arbitrary code execution on Windows systems when the software is installed for all users.
Which versions of IBM i Access Client Solutions are affected by CVE-2026-14875?
CVE-2026-14875 affects versions 1.1.2.0 through 1.1.9.13 of IBM i Access Client Solutions.
Is there a workaround for CVE-2026-14875?
Currently, the best mitigation for CVE-2026-14875 is to ensure that the software is not installed for all users or to apply the latest update.