What is CVE-2026-17266?
CVE-2026-17266 affects IBM i versions 7.3, 7.4, 7.5, and 7.6, allowing a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. This is a 'path traversal' vulnerability that can lead to unauthorized data exposure. Immediate application of security patches from IBM is recommended.
Azərbaycanca: CVE-2026-17266, IBM i əməliyyat sisteminin 7.3, 7.4, 7.5 və 7.6 versiyalarına təsir edən zəiflikdir. Bu qüsur 'path traversal' prinsipi ilə uzaqdan autentifikasiya olunmuş hücumçuya məhdud qovluqdan kənar həssas məlumatları əldə etməyə imkan verir. Sistem administratorlarına IBM tərəfindən təqdim ediləcək təhlükəsizlik yamalarını tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: IBM
FAQ2
Which versions of IBM i are affected by CVE-2026-17266?
CVE-2026-17266 affects IBM i versions 7.3, 7.4, 7.5, and 7.6.
What can an attacker achieve by exploiting CVE-2026-17266?
A remote authenticated attacker can exploit the path traversal vulnerability to obtain sensitive information from outside the restricted directory.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.