CVE-2026-18869: IBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ]
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.
Other sources
IBM i could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11371 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11382 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11383 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11384
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be remotely authenticated to the IBM i FTP service. No user interaction is required.
What could an attacker reach if exploitation succeeds?
An attacker could bypass security restrictions and access internal network services by abusing improperly validated FTP PORT and EPRT commands.
Which IBM i releases are identified as affected?
IBM i 7.3, 7.4, 7.5, and 7.6 are identified as affected.