Remote Information Disclosure Vulnerability in IBM i Software
CVE-2026-17266
6.5MEDIUM
What is CVE-2026-17266?
A remote authenticated attacker could exploit a vulnerability in IBM i 7.6, 7.5, 7.4, and 7.3 to gain unauthorized access to sensitive information. This issue arises due to improper limitations on pathnames that can be accessed, potentially allowing attackers to navigate to restricted directories. Organizations using these versions of IBM i should review their security configurations and apply appropriate patches to mitigate this risk.
Affected Version(s)
i 7.6
i 7.5
i 7.4