CVE-2026-17499: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Other sources
IBM i could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Patch SJ11305 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Patch SJ11306 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Patch SJ11307 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Patch SJ11308
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The issue requires local attacker access to IBM i.
What is the potential impact of successful exploitation?
A local attacker could execute arbitrary commands because special elements used in an OS command are not properly neutralized.