ZeroHour

CVE-2026-17057

large

Missing authentication in IBM i 7.3–7.6 enables DoS and data tampering

CVSS 3.1
9.1 critical
EPSS
<1%p31
Published
()
Modified
AI analysis

CVE-2026-17057 is a critical missing-authentication vulnerability (CWE-306) in IBM i, affecting all currently supported releases: 7.3, 7.4, 7.5, and 7.6. An unauthenticated remote attacker can reach an affected critical function over the network with no privileges or user interaction and trigger a denial of service and unauthorized modification of data; the CVSS vector indicates high integrity and availability impact with no confidentiality loss. The initial advisory data does not name the specific vulnerable interface or service, so defenders should consult the IBM PSIRT bulletin for the affected component. Any organization running IBM i 7.3, 7.4, 7.5, or 7.6 is potentially affected. There is currently no public proof-of-concept, no known in-the-wild exploitation, and the vulnerability is not in CISA KEV; EPSS estimates only a 0.4% chance of exploitation in the next 30 days.

What to do: Monitor the IBM PSIRT security bulletin for CVE-2026-17057 and apply the corrective IBM i PTFs it specifies for 7.3, 7.4, 7.5, and 7.6 as soon as they are published. In the interim, restrict network access to IBM i servers—particularly any reachable from untrusted networks—and watch for unexpected service disruption or data changes. Given the high integrity and availability impact, prioritize patching systems that host critical transactional or ERP workloads.

Affected
IBM i7.3, 7.4, 7.5, and 7.6 (all releases listed in the advisory; specific fix levels to be confirmed via IBM PSIRT)
Estimated exposure
largetens of thousands of systems plausibly affected (global IBM i install base commonly cited at ~100,000+ deployments; most run internal workloads behind… — Estimate based on widely cited IBM/community figures of roughly 100,000+ IBM i installations worldwide, reduced to account for systems that are already patched, retired, or not reachable by an unauthenticated network attacker.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.

Vendors
ibm
Products
i
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.