CVE-2026-16693: IBM i is Affected By Cryptographic Algorithm Weakness in DCM []
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.
Other sources
IBM i could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11156 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.5Patch SJ11159 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.4Patch SJ11158 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.3Patch SJ11157
Event History
Frequently Asked Questions
What level of access does an attacker need?
The description states that exploitation requires a remote authenticated attacker. The CVSS vector also indicates high privileges are required, although it lists the attack vector as local, so the access path is inconsistent in the supplied data.
What is the expected security impact if exploited?
The CVSS metrics indicate high confidentiality impact, with no integrity or availability impact. The described outcome is disclosure of sensitive information.