CVE-2026-16906: IBM i is Affected By Multiple Vulnerabilities in Domain Name System
IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command.
Other sources
IBM i could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ10931 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11010
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16906?
The severity of CVE-2026-16906 is high, with a CVSS score of 8.8.
How do I fix CVE-2026-16906?
To mitigate CVE-2026-16906, update your IBM i system to the latest patched version as provided by IBM.
What systems are affected by CVE-2026-16906?
CVE-2026-16906 affects IBM i versions 7.6 and 7.5.
What type of vulnerability is CVE-2026-16906?
CVE-2026-16906 is classified as an OS command injection vulnerability.
Can CVE-2026-16906 be exploited remotely?
Yes, CVE-2026-16906 can be exploited by a remote authenticated attacker.