What is CVE-2026-17082?
This vulnerability allows a remote authenticated attacker to gain elevated privileges on IBM i systems due to improper validation of a client-supplied profile name. An attacker could exploit this flaw by sending specially crafted input to perform unauthorized actions. Affected systems should be promptly patched with the vendor's released update.
Azərbaycanca: Bu zəiflik autentifikasiya olunmuş uzaqdan hücumçuya təqdim etdiyi profil adının yanlış yoxlanılması səbəbindən IBM i sistemlərində yüksək imtiyazlar əldə etməyə imkan verir. Hücumçu xüsusi hazırlanmış profil adı vasitəsilə icazəsiz əməliyyatlar həyata keçirə bilər. Təsirə məruz qalan sistemlərdə dərhal istehsalçı tərəfindən təqdim olunan yamaqlar tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-20; shared vendor: IBM
FAQ1
How can a remote authenticated attacker exploit improper profile name validation on IBM i systems to gain elevated privileges?
An attacker can send specially crafted input using a client-supplied profile name to perform unauthorized actions and gain elevated privileges on the system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.