CVE-2026-17075
published 2026-08-13CVE-2026-17075: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of…
PriorityP347high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
0.31%
24.0th percentile
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | i | — | — |
| ibm | i | — | — |
| ibm | i | — | — |
| ibm | i | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM i 7.3/7.4/7.5/7.6 improper authorization
vuldb·2026-08-13·CVSS 6.5
CVE-2026-17075 [MEDIUM] IBM i 7.3/7.4/7.5/7.6 improper authorization
A vulnerability was found in IBM i 7.3/7.4/7.5/7.6 and classified as very critical. This vulnerability affects unknown code. Such manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-17075. The attack can be executed remotely. There is not any exploit available.
GHSA
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.
ghsa_unreviewed·2026-08-13
CVE-2026-17075 [MEDIUM] CWE-287 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper validation of authentication tokens.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published