ZeroHour

CVE-2026-16826

mass

OS Command Injection in IBM i 7.3-7.6 Lets Local Users Run Arbitrary Commands

CVSS 3.1
7.8 high
EPSS
<1%p3
Published
()
Modified
AI analysis

CVE-2026-16826 is an OS command injection flaw (CWE-78) in IBM i releases 7.3, 7.4, 7.5, and 7.6, in which special elements (command metacharacters) are improperly neutralized before being used in an operating-system command. A local attacker with a low-privileged account on an affected IBM i system could supply crafted input containing such special characters, causing arbitrary commands to be executed. Successful exploitation grants arbitrary command execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 7.8, AV:L/PR:L). Affected organizations are those running any of the four listed IBM i releases, which spans essentially the full affected release set named by IBM. As of now there is no known exploitation: the flaw is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS estimates only a ~0.1% probability of exploitation within 30 days (3rd percentile).

What to do: Consult IBM's security bulletin for CVE-2026-16826 and apply the IBM-provided PTF fixes to every IBM i partition running 7.3, 7.4, 7.5, or 7.6, following your standard PTF testing process. Until patched, prioritize systems that grant interactive sign-on (e.g., 5250 or SSH) to broad or low-privileged user populations and review local accounts for unnecessary access. Because exploitation requires local access, restricting remote-access paths into IBM i partitions and monitoring for unexpected command execution will reduce exposure.

Affected
IBM i7.3, 7.4, 7.5, 7.6
Estimated exposure
mass~100,000+ organizations / on the order of several hundred thousand IBM i systems and partitions running the affected releases 7.3-7.6 — Based on widely cited industry estimates of the IBM i installed base (~100,000+ customer organizations and hundreds of thousands of systems/partitions, most of which run currently supported releases); this is an estimate, as IBM does not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Vendors
ibm
Products
i
Weakness
CWE-78
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.