What is CVE-2026-16904?
IBM i versions 7.3 through 7.6 contain improper privilege management during monitor owner reassignment, allowing a remote authenticated attacker to execute arbitrary commands. Exploitation could lead to full system compromise, requiring immediate patching.
Azərbaycanca: IBM i əməliyyat sisteminin 7.3-dən 7.6-ya qədər versiyaları monitor sahibinin yenidən təyin edilməsi zamanı düzgün olmayan imtiyaz idarəetməsi səbəbindən uzaqdan autentifikasiya olunmuş hücumçuya ixtiyari əmrlər icra etməyə imkan verir. Bu zəiflikdən istifadə edən şəxs sistem üzərində nəzarəti ələ keçirə bilər, ona görə də dərhal yamaqlanmalıdır.
Related CVEs
link basis: same weakness class CWE-269; shared vendor: IBM
FAQ2
What impact could CVE-2026-16904 have?
A remote authenticated attacker exploiting this vulnerability could gain full system compromise.
Which versions of IBM i are affected by CVE-2026-16904?
IBM i versions 7.3 through 7.6 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.