Time-of-Check to Time-of-Use Vulnerability in IBM i by IBM
CVE-2026-18069
6MEDIUM
What is CVE-2026-18069?
A time-of-check to time-of-use (TOCTOU) race condition vulnerability in IBM i versions 7.6, 7.5, 7.4, and 7.3 allows a local attacker to gain unauthorized ownership of file system objects. This flaw could lead to significant security risks as it enables the manipulation of file ownership, potentially compromising sensitive data and system integrity. IBM has released a security advisory outlining this issue and recommended actions for mitigation.
Affected Version(s)
i 7.6
i 7.5
i 7.4