What is CVE-2026-16967?
CVE-2026-16967 is a time-of-check to time-of-use (TOCTOU) race condition vulnerability involving symbolic links in IBM i versions 7.3, 7.4, 7.5, and 7.6. It could allow a remote authenticated attacker to gain unauthorized access to system objects. Users should apply the security updates provided by IBM.
Azərbaycanca: CVE-2026-16967 IBM i əməliyyat sisteminin 7.3, 7.4, 7.5 və 7.6 versiyalarında simvolik keçidlərlə bağlı time-of-check to time-of-use (TOCTOU) race condition zəifliyidir. Bu, uzaqdan autentifikasiya olunmuş hücumçuya sistem obyektlərinə icazəsiz giriş imkanı yarada bilər. İstifadəçilərə IBM tərəfindən təqdim olunan təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: IBM
FAQ2
What privileges must an attacker have to exploit CVE-2026-16967?
The attacker must be remote authenticated to the system to exploit this vulnerability.
Which versions of IBM i are affected by CVE-2026-16967?
The vulnerability affects IBM i versions 7.3, 7.4, 7.5, and 7.6.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.