CVE-2026-17057
largeMissing authentication in IBM i 7.3–7.6 enables DoS and data tampering
CVE-2026-17057 is a critical missing-authentication vulnerability (CWE-306) in IBM i, affecting all currently supported releases: 7.3, 7.4, 7.5, and 7.6. An unauthenticated remote attacker can reach an affected critical function over the network with no privileges or user interaction and trigger a denial of service and unauthorized modification of data; the CVSS vector indicates high integrity and availability impact with no confidentiality loss. The initial advisory data does not name the specific vulnerable interface or service, so defenders should consult the IBM PSIRT bulletin for the affected component. Any organization running IBM i 7.3, 7.4, 7.5, or 7.6 is potentially affected. There is currently no public proof-of-concept, no known in-the-wild exploitation, and the vulnerability is not in CISA KEV; EPSS estimates only a 0.4% chance of exploitation in the next 30 days.
What to do: Monitor the IBM PSIRT security bulletin for CVE-2026-17057 and apply the corrective IBM i PTFs it specifies for 7.3, 7.4, 7.5, and 7.6 as soon as they are published. In the interim, restrict network access to IBM i servers—particularly any reachable from untrusted networks—and watch for unexpected service disruption or data changes. Given the high integrity and availability impact, prioritize patching systems that host critical transactional or ERP workloads.
| IBM i | 7.3, 7.4, 7.5, and 7.6 (all releases listed in the advisory; specific fix levels to be confirmed via IBM PSIRT) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
- Vendors
- ibm
- Products
- i
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.