IBM security advisory (AV26-997)
Canada’s Cyber Centre urges patches for IBM DataStage, Guardium, and IBM i, including CVE-2026-84414.
Canadian Centre for Cyber Security advisory AV26-997, dated October 5, 2026, says IBM products were affected as of September 29, 2026. The notice covers DataStage on Cloud Pak for Data 5.4.0.0, Guardium Data Protection 12.2, and IBM i 7.3, 7.4, 7.5, and 7.6. IBM i is affected by an incorrect permission assignment in Network Authentication Service, tracked as CVE-2026-84414. Administrators are told to review IBM’s links and apply updates; exploitation is not mentioned.
- Advisory AV26-997 covers three IBM product families.
- CVE-2026-84414 is an incorrect permission flaw in IBM i authentication.
- Affected IBM i versions are 7.3, 7.4, 7.5, and 7.6.
- No in-the-wild exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-844147.8—Local arbitrary file ownership change in IBM ipublished · IBM i
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84414 | Local arbitrary file ownership change in IBM i IBM i 7.6, 7.5, 7.4, and 7.3 let a local authenticated user change the ownership of arbitrary files because an attacker-controlled file path is not validated correctly. The attacker must already be signed on to the system; no user interaction is required, and the issue is scoped to the local system. Successful use yields high impact on confidentiality, integrity, and availability (CVSS 3.1 base 7.8), including taking ownership of files the attacker should not control. It affects IBM i installations on those four releases. It is not listed in CISA KEV, and no public proof-of-concept is known. Do: Apply the IBM security fix (PTF) for this issue on IBM i 7.3, 7.4, 7.5, and 7.6 as soon as it is available from IBM Fix Central or your vendor bulletin. Until then, limit which local profiles can run the affected function, and review unexpected ownership changes on sensitive objects. This is not remotely exploitable; prioritize systems where many users already have a local sign-on. |
Full article98 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-997
Date: October 5, 2026
As of September 29, 2026, IBM is affected by vulnerabilities in the following products:
- DataStage on Cloud Pak for Data
- Version 5.4.0.0
- Guardium Data Protection
- Version 12.2
- IBM i
- Version 7.3, 7.4, 7.5 and 7.6
The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-997