Race Condition Vulnerability in IBM i Systems Across Multiple Versions
CVE-2026-16967

8.5HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-16967?

A vulnerability exists in IBM i systems where a remote authenticated attacker could exploit a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links. This flaw may allow the attacker to gain unauthorized access to critical system objects, compromising the integrity and confidentiality of the system.

Affected Version(s)

i 7.6

i 7.5

i 7.4

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.