CVE-2026-18527
largeUnauthenticated Privilege Escalation in IBM Administration Runtime Expert for i
IBM Application Runtime Expert (ARE) for i version 1R1M0 contains an unauthenticated privilege escalation flaw (CWE-384, session fixation) caused by improper processing in the ARE GUI component. A remote attacker with network access to the component can trigger this processing so that actions execute under another user's already-authenticated profile. The attacker gains elevated privileges on the affected IBM i system, with high impact to confidentiality, integrity, and availability per the CVSS 9.9 (critical) score. Organizations running the ARE 1R1M0 licensed program on IBM i are affected; practical exploitability depends on the ARE component being reachable over the network. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS shows only a 0.3% 30-day exploitation probability, so no exploitation has been confirmed.
What to do: Check whether ARE 1R1M0 is installed on your IBM i partitions and whether its GUI/service component is reachable from the network; restrict network access to it until a fix is available. Monitor the IBM PSIRT advisory and IBM Fix Central for the remediation PTF or updated ARE build for 1R1M0 and apply it once published. Review IBM i audit journals for actions taken under unexpected user profiles as a precaution.
| IBM Administration Runtime Expert for i (Application Runtime Expert, ARE) | 1R1M0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
- Weakness
- CWE-384
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.