CVE-2026-18527: IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Application Runtime Expert for i (ARE)to a version that resolves this vulnerability.Fixed in 1R1M0Patch SJ11185 - Compensating control
Given the note that after applying this PTF the legacy ARE GUI is nonfunctional, avoid using the legacy ARE GUI until it is restored; consider restricting access to any remaining ARE GUI/admin endpoints to prevent unauthenticated exploitation while remediation is being validated.
Event History
Frequently Asked Questions
Does an attacker need valid credentials to exploit this issue?
The vulnerability description states that an unauthenticated remote attacker can exploit the ARE GUI component. Successful exploitation can cause actions to run under another user's authenticated profile.
Which deployment is specifically identified as affected?
The affected software is identified as IBM Administration Runtime Expert for i 1R1M0, also referred to as IBM Application Runtime Expert (ARE) for i. The provided data does not identify other versions or configurations.