What is CVE-2026-17417?
CVE-2026-17417 is a vulnerability affecting IBM i versions 7.3, 7.4, 7.5, and 7.6, allowing a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters. Organizations should immediately apply the security patches provided by IBM.
Azərbaycanca: CVE-2026-17417, IBM i əməliyyat sisteminin 7.3, 7.4, 7.5 və 7.6 versiyalarına təsir edən, uzaqdan autentifikasiya olunmuş hücumçunun shell metacharakterlərinin düzgün neytrallaşdırılmaması səbəbindən ixtiyari əmrlər icra etməsinə imkan verən boşluqdur. Təsirə məruz qalan versiyaları istifadə edən təşkilatlar dərhal IBM tərəfindən təqdim edilən təhlükəsizlik yamalarını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: IBM
FAQ2
Does exploiting CVE-2026-17417 require the attacker to be authenticated?
Yes, the CVE-2026-17417 vulnerability allows a remote authenticated attacker to execute arbitrary commands.
Which versions of IBM i are affected by CVE-2026-17417?
This vulnerability affects IBM i versions 7.3, 7.4, 7.5, and 7.6.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.