CVE-2026-7870: IBM i is Affected by Privilege Escalation []
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.
Other sources
IBM i could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Release5770-SS1 (7.6)to a version that resolves this vulnerability.Patch SJ09689 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.6)to a version that resolves this vulnerability.Patch SJ09666 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.6)to a version that resolves this vulnerability.Patch SJ10017 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.6)to a version that resolves this vulnerability.Patch SJ09859 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.5)to a version that resolves this vulnerability.Patch SJ09688 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.5)to a version that resolves this vulnerability.Patch SJ09665 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.5)to a version that resolves this vulnerability.Patch SJ09699 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.5)to a version that resolves this vulnerability.Patch SJ10015 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.5)to a version that resolves this vulnerability.Patch SJ09855 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.4)to a version that resolves this vulnerability.Patch SJ09690 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.4)to a version that resolves this vulnerability.Patch SJ09664 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.4)to a version that resolves this vulnerability.Patch SJ09701 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.4)to a version that resolves this vulnerability.Patch SJ10028 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.4)to a version that resolves this vulnerability.Patch SJ09851 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.3)to a version that resolves this vulnerability.Patch SJ09691 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.3)to a version that resolves this vulnerability.Patch SJ09663 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.3)to a version that resolves this vulnerability.Patch SJ10018 - Upgrade
Upgrade
IBM i Release5770-SS1 (7.3)to a version that resolves this vulnerability.Patch SJ09837 - Compensating control
IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7870?
CVE-2026-7870 has a severity rating of 8.8, which is classified as high risk.
How does CVE-2026-7870 affect IBM i systems?
CVE-2026-7870 allows a malicious actor to gain elevated privileges via an unqualified library call on IBM i systems.
Which versions of IBM i are affected by CVE-2026-7870?
IBM i versions 7.3, 7.4, 7.5, and 7.6 are affected by CVE-2026-7870.
What can be done to fix CVE-2026-7870?
To mitigate CVE-2026-7870, apply the recommended PTFs available for your IBM i version.
What is the nature of the vulnerability in CVE-2026-7870?
CVE-2026-7870 is a privilege escalation vulnerability that can allow user-controlled code to execute with administrator permissions.