Stored Cross-Site Scripting Vulnerability in IBM i Products
CVE-2026-16694

6.4MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-16694?

IBM i versions 7.3 through 7.6 are susceptible to a stored cross-site scripting vulnerability. This issue allows authenticated users to insert arbitrary JavaScript code into the Web UI. This malicious code can alter the intended functionality of the application and may lead to the disclosure of sensitive credentials during trusted sessions. Organizations using affected versions should take immediate action to mitigate this risk as part of their security best practices.

Affected Version(s)

i 7.6

i 7.5

i 7.4

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.