CVE-2026-17262: IBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ]
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.
Other sources
IBM i could allow a local attacker to cause a denial of service due to improper validation of FTP authentication commands.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6 (Release 5770-TC1)to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11371 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11382 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11383 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11384
Event History
Frequently Asked Questions
Which IBM i releases are identified as affected?
The affected releases listed are IBM i 7.6, 7.5, 7.4, and 7.3.
What access or interaction prerequisites are indicated for exploitation?
The description characterizes the attacker as local. The supplied CVSS vector indicates no privileges and no user interaction are required.
What security impact is reflected in the supplied CVSS metrics?
The CVSS metrics indicate no confidentiality impact, with low integrity and availability impact. The description specifically identifies denial of service resulting from improper validation of FTP authentication commands.