PT-2026-71271 · Ibm · Ibm I

CVE-2026-17417

·

Published

2026-08-12

·

Updated

2026-08-13

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM i versions 7.3 through 7.6
Description Remote authenticated attackers can execute arbitrary commands due to improper neutralization of shell metacharacters. This occurs when the system fails to properly filter or escape special characters that have a specific meaning to the command shell, allowing an attacker to inject their own commands into a legitimate request.
Recommendations Update IBM i versions 7.3 through 7.6 to a patched release.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17417

Affected Products

Ibm I