ZeroHour

CVE-2026-18527

large

Unauthenticated Privilege Escalation in IBM Administration Runtime Expert for i

CVSS 3.1
9.9 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

IBM Application Runtime Expert (ARE) for i version 1R1M0 contains an unauthenticated privilege escalation flaw (CWE-384, session fixation) caused by improper processing in the ARE GUI component. A remote attacker with network access to the component can trigger this processing so that actions execute under another user's already-authenticated profile. The attacker gains elevated privileges on the affected IBM i system, with high impact to confidentiality, integrity, and availability per the CVSS 9.9 (critical) score. Organizations running the ARE 1R1M0 licensed program on IBM i are affected; practical exploitability depends on the ARE component being reachable over the network. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS shows only a 0.3% 30-day exploitation probability, so no exploitation has been confirmed.

What to do: Check whether ARE 1R1M0 is installed on your IBM i partitions and whether its GUI/service component is reachable from the network; restrict network access to it until a fix is available. Monitor the IBM PSIRT advisory and IBM Fix Central for the remediation PTF or updated ARE build for 1R1M0 and apply it once published. Review IBM i audit journals for actions taken under unexpected user profiles as a precaution.

Affected
IBM Administration Runtime Expert for i (Application Runtime Expert, ARE)1R1M0
Estimated exposure
largetens of thousands of IBM i systems (ARE 1R1M0 ships with IBM i, whose global installed base is estimated at roughly 100,000+ systems), with a smaller subset… — ARE for i is distributed with the IBM i operating system, so the potential install base follows IBM i's estimated installed base of around 100,000 systems, discounted by the requirement that the ARE service component be exposed to the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.

Weakness
CWE-384
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.