CVE-2026-16892: IBM i is Affected By An Improper Authentication Vulnerability in Network Authentication Service []
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.
Other sources
IBM i could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Patch SJ11089 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Patch SJ11090 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Patch SJ11091 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Patch SJ11092
Event History
Frequently Asked Questions
Does an attacker need valid access before exploiting this issue?
Yes. The issue is described as exploitable by a remote authenticated attacker, so the attacker must already be authenticated. No user interaction is required.
Which IBM i releases should be included in remediation scope?
IBM i 7.3, 7.4, 7.5, and 7.6 are identified as affected.
What security impact is indicated by the available severity data?
The severity is medium with a CVSS score of 5.4. The vector indicates low confidentiality and integrity impact and no availability impact.