CVE-2026-16695: IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Other sources
IBM i Access Family could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Access Client Solutionsto a version that resolves this vulnerability.Fixed in 1.1.9.14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch LCD8-2010-43 - Upgrade
Upgrade
IBM i Access Client Solutionsto a version that resolves this vulnerability.Patch SJ11046 - Upgrade
Upgrade
IBM i Access Client Solutionsto a version that resolves this vulnerability.Patch SJ11044 - Upgrade
Upgrade
IBM i Access Client Solutionsto a version that resolves this vulnerability.Patch SJ11045 - Upgrade
Upgrade
IBM i Access Client Solutionsto a version that resolves this vulnerability.Patch SJ11043
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16695?
The severity of CVE-2026-16695 is rated high with a score of 7.8.
What vulnerability does CVE-2026-16695 describe?
CVE-2026-16695 describes multiple vulnerabilities in IBM i Access Client Solutions that allow local attackers to execute arbitrary code.
How can I mitigate CVE-2026-16695?
To mitigate CVE-2026-16695, users should upgrade IBM i Access Client Solutions to the latest version available.
What systems are affected by CVE-2026-16695?
CVE-2026-16695 affects IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13.
What type of attack is facilitated by CVE-2026-16695?
CVE-2026-16695 facilitates OS command injection attacks that enable arbitrary code execution.