ZeroHour

CVE-2026-17499

large

Local OS Command Injection in IBM i 7.3–7.6 Allows Arbitrary Command Execution

CVSS 3.1
7.8 high
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-17499 is an OS command injection flaw (CWE-78) in IBM i versions 7.3, 7.4, 7.5, and 7.6, caused by improper neutralization of special elements passed to an operating system command. A local attacker who already has a low-privileged account on an affected IBM i system can trigger the flaw to execute arbitrary commands. Because the CVSS impact ratings for confidentiality, integrity, and availability are all high, successful exploitation likely lets the attacker run commands beyond their normal privilege level, potentially compromising the whole partition. Any organization running IBM i on the affected releases is exposed, though exploitation requires an attacker to first obtain local access rather than being exploitable over the network. There are currently no known public proof-of-concepts, the flaw is not in CISA's KEV catalog, and EPSS assigns it a 0.1% probability of exploitation in the next 30 days.

What to do: Review the IBM security bulletin for CVE-2026-17499 and apply the IBM-provided PTFs for your release level (7.3, 7.4, 7.5, or 7.6). Until patched, limit sign-on access to affected partitions to trusted users and audit local accounts on IBM i hosts that serve untrusted or application-level users, since the flaw requires a local foothold.

Affected
IBM i7.3, 7.4, 7.5, 7.6
Estimated exposure
large≈100,000 IBM i systems worldwide, with only those on 7.3–7.6 granting local low-privileged access practically exposed — IBM i (formerly AS/400/iSeries) runs on roughly 100,000+ systems at mid-size and large enterprises per long-standing IBM and community install-base estimates, and this flaw is local-only, so systems where attackers do not already hold a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Vendors
ibm
Products
i
Weakness
CWE-78
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.