CVE-2026-18669: IBM i is Affected By A Privilege Escalation Vulnerability []
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
Other sources
IBM i is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i activation engine (PTF for privilege escalation via RCE)to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11009 - Upgrade
Upgrade
IBM i activation engine (PTF for privilege escalation via RCE)to a version that resolves this vulnerability.Fixed in 7.5Patch SJ10978 - Upgrade
Upgrade
IBM i activation engine (PTF for privilege escalation via RCE)to a version that resolves this vulnerability.Fixed in 7.4Patch SJ10977 - Upgrade
Upgrade
IBM i activation engine (PTF for privilege escalation via RCE)to a version that resolves this vulnerability.Fixed in 7.3Patch SJ10976
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18669?
The severity of CVE-2026-18669 is high, with a CVSS score of 8.8.
What systems are affected by CVE-2026-18669?
CVE-2026-18669 affects IBM i versions 7.6, 7.5, 7.4, and 7.3.
How do I fix CVE-2026-18669?
To fix CVE-2026-18669, ensure that your IBM i systems are updated with the latest security patches provided by IBM.
What type of vulnerability is CVE-2026-18669?
CVE-2026-18669 is a privilege escalation vulnerability that allows an authenticated attacker to execute malicious scripts with root authority.
What are the potential impacts of CVE-2026-18669?
The potential impacts of CVE-2026-18669 include unauthorized access to sensitive data and complete control over the affected IBM i system.