CVE-2026-17203: IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
Other sources
IBM Administration Runtime Expert for i could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Administration Runtime Expert for i (ARE)to a version that resolves this vulnerability.Fixed in 1R1M0Patch SJ11185
Event History
Frequently Asked Questions
Does exploitation require authentication?
The vulnerability description says a remote authenticated attacker could exploit the issue, while the CVSS vector lists PR:N (no privileges required). The provided data does not resolve this discrepancy, so treat authentication requirements as needing vendor confirmation during triage.