CVE-2026-16826: IBM i is Affected By Multiple Vulnerabilities in Debug Server
Published Aug 31, 2026
·Updated
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Other sources
IBM i could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
— IBM
Affected Software
4 affected components
IBM i<=7.6
IBM i<=7.5
IBM i<=7.4
IBM i<=7.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11305 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11306 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11307 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11308
Event History
Aug 31, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 4, 2026
CVE Published
via MITRE·04:41 PM
Data Sourced
via MITRE·04:41 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness