CVE-2026-84414: IBM i is Affected By An Incorrect Permission Assignment Vulnerability in Network Authentication Service []
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
Other sources
IBM i could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Patch SJ11607 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Patch SJ11608 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Patch SJ11609 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Patch SJ11610
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs local authenticated access to an affected IBM i system. The issue affects IBM i 7.3, 7.4, 7.5, and 7.6.
What level of access could an attacker gain through exploitation?
A local authenticated attacker could change ownership of arbitrary files by supplying a file path that is not properly validated. This can impact the confidentiality, integrity, and availability of affected systems.