CVE-2026-16941: IBM i is Affected By An Incorrect Authorization Vulnerability []
IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization.
Other sources
IBM i could allow a remote authenticated attacker to modify certain system messages due to improper authorization.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11201 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11210 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11211
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must be remotely authenticated and have low-level privileges. No user interaction is required.
What is the impact if the issue is exploited?
A successful attacker could modify certain system messages. The provided severity vector indicates an integrity impact, with no stated confidentiality or availability impact.
Which IBM i releases are identified as affected?
IBM i 7.4, 7.5, and 7.6 are identified as affected.