What is CVE-2026-17111?
IBM i versions 7.3, 7.4, 7.5, and 7.6 are vulnerable to SQL injection. A remote attacker can send specially crafted SQL statements to view, add, modify, or delete information in the back-end database. Immediate patching is required to mitigate this vulnerability.
Azərbaycanca: IBM i əməliyyat sisteminin 7.3, 7.4, 7.5 və 7.6 versiyaları SQL injection zəifliyinə məruz qalır. Uzaqdan olan təcavüzkar xüsusi hazırlanmış SQL sorğuları göndərərək arxa plandakı verilənlər bazasında məlumatlara baxa, əlavə edə, dəyişdirə və ya silə bilər. Bu boşluğu aradan qaldırmaq üçün dərhal təhlükəsizlik yeniləmələri tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: IBM
FAQ2
Which versions of IBM i are affected by the CVE-2026-17111 SQL injection vulnerability?
IBM i versions 7.3, 7.4, 7.5, and 7.6 are affected.
What actions can a remote attacker perform by exploiting CVE-2026-17111?
A remote attacker can send specially crafted SQL statements to view, add, modify, or delete information in the back-end database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.