What is CVE-2026-16694?
CVE-2026-16694 is a stored cross-site scripting (XSS) vulnerability affecting IBM i versions 7.3, 7.4, 7.5, and 7.6. An authenticated user can embed arbitrary JavaScript code in the Web UI, potentially leading to credential disclosure within a trusted session. Affected users should apply the security patches provided by IBM immediately.
Azərbaycanca: CVE-2026-16694, IBM i əməliyyat sisteminin 7.3, 7.4, 7.5 və 7.6 versiyalarında aşkarlanan stored cross-site scripting (XSS) zəifliyidir. Bu zəiflik autentifikasiya olunmuş istifadəçiyə Web UI-da JavaScript kodu yerləşdirməyə imkan verir ki, bu da etibarlı sessiyada məxfi məlumatların oğurlanmasına səbəb ola bilər. Təsirlənmiş istifadəçilərə dərhal IBM tərəfindən təqdim olunan təhlükəsizlik yamalarını tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: IBM
FAQ2
Which versions of IBM i are affected by CVE-2026-16694?
This stored XSS vulnerability affects IBM i versions 7.3, 7.4, 7.5, and 7.6.
What risk arises when CVE-2026-16694 is exploited?
An authenticated user can embed JavaScript code in the Web UI, potentially leading to credential disclosure within a trusted session.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.