CVE-2026-17499
largeLocal OS Command Injection in IBM i 7.3–7.6 Allows Arbitrary Command Execution
CVE-2026-17499 is an OS command injection flaw (CWE-78) in IBM i versions 7.3, 7.4, 7.5, and 7.6, caused by improper neutralization of special elements passed to an operating system command. A local attacker who already has a low-privileged account on an affected IBM i system can trigger the flaw to execute arbitrary commands. Because the CVSS impact ratings for confidentiality, integrity, and availability are all high, successful exploitation likely lets the attacker run commands beyond their normal privilege level, potentially compromising the whole partition. Any organization running IBM i on the affected releases is exposed, though exploitation requires an attacker to first obtain local access rather than being exploitable over the network. There are currently no known public proof-of-concepts, the flaw is not in CISA's KEV catalog, and EPSS assigns it a 0.1% probability of exploitation in the next 30 days.
What to do: Review the IBM security bulletin for CVE-2026-17499 and apply the IBM-provided PTFs for your release level (7.3, 7.4, 7.5, or 7.6). Until patched, limit sign-on access to affected partitions to trusted users and audit local accounts on IBM i hosts that serve untrusted or application-level users, since the flaw requires a local foothold.
| IBM i | 7.3, 7.4, 7.5, 7.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
- Vendors
- ibm
- Products
- i
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.