IBM Application Runtime Expert for i Vulnerability Allowing Remote Privilege Escalation
CVE-2026-18527

9.9CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
28 August 2026

What is CVE-2026-18527?

The vulnerability in IBM Application Runtime Expert (ARE) for i arises from a flaw in the ARE GUI component that permits an unauthenticated remote attacker to exploit this weakness. By executing specific actions under the context of an authenticated user's profile, the attacker could gain elevated privileges, leading to unauthorized access and potential compromise of the IBM i system.

Affected Version(s)

Administration Runtime Expert for i 1R1M0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.