Unauthorized Access Vulnerability in IBM i Products by IBM
CVE-2026-16908

8.5HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-16908?

A path traversal vulnerability in IBM i versions 7.3 through 7.6 allows remote authenticated attackers to gain unauthorized access to arbitrary objects, potentially leading to sensitive data exposure and system compromise. This issue can be exploited by manipulating file paths, allowing unauthorized navigation through the file system hierarchy. Organizations are advised to apply the necessary patches provided by IBM to mitigate this risk.

Affected Version(s)

i 7.6

i 7.5

i 7.4

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.