Arbitrary Code Execution Vulnerability in IBM i Access Client Solutions
CVE-2026-13094

7.8HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
12 August 2026

What is CVE-2026-13094?

IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 contain a vulnerability that allows for arbitrary code execution on Windows systems. This issue arises when the software is installed for all users, making the configuration file publicly writable. An attacker could exploit this weakness to execute malicious code, leading to potential unauthorized access and control over the affected system.

Affected Version(s)

i Access Client Solutions 1.1.2.0 <= 1.1.9.13

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.