CVE-2026-2311: IBM i is affected by a privilege escalation vulnerability in Web Administration GUI []
IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check. A malicious actor could cause user-controlled code to run with administrator privilege.
Other sources
IBM i is vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check. A malicious actor could cause user-controlled code to run with administrator privilege.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2311?
CVE-2026-2311 is classified as a privilege escalation vulnerability affecting IBM i versions 7.2 to 7.6.
How do I fix CVE-2026-2311?
To fix CVE-2026-2311, apply the latest security patches provided by IBM for your version of IBM i.
What systems are affected by CVE-2026-2311?
CVE-2026-2311 affects IBM i versions 7.2, 7.3, 7.4, 7.5, and 7.6.
What can an attacker do with CVE-2026-2311?
An attacker exploiting CVE-2026-2311 could execute user-controlled code with administrative privileges.
Is there a workaround for CVE-2026-2311?
Currently, there are no recommended workarounds for CVE-2026-2311; applying patches is the advised approach.