What is CVE-2026-16867?
CVE-2026-16867 is a vulnerability affecting IBM i versions 7.3, 7.4, 7.5, and 7.6. Due to improper authentication during NTLM session negotiation, a remote attacker could access server resources with the privileges of an authenticated user. Applying security patches is recommended for affected systems.
Azərbaycanca: CVE-2026-16867 IBM i əməliyyat sisteminin 7.3, 7.4, 7.5 və 7.6 versiyalarına təsir edən zəiflikdir. Bu qüsur NTLM sessiya danışıqları zamanı düzgün olmayan autentifikasiya səbəbindən uzaqdan hücum edən şəxsə autentifikasiya olunmuş istifadəçi səlahiyyətləri ilə server resurslarına giriş imkanı yaradır. Təsirə məruz qalan sistemlərdə təhlükəsizlik yamaqlarının tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: IBM
FAQ2
Which versions of the IBM i operating system are affected by CVE-2026-16867?
This vulnerability affects IBM i versions 7.3, 7.4, 7.5, and 7.6.
What authentication mechanism flaw does CVE-2026-16867 stem from?
This vulnerability stems from improper authentication during NTLM session negotiation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.