← Terug naar overzicht

CVE-2026-18527 affects IBM Application Runtime Expert (ARE) for i version 1R1M0. The vulnerability exists in the ARE GUI component and allows a remote, unauthenticated attacker to gain elevated privileges on the IBM i system. By exploiting this flaw, an attacker can execute actions under another authenticated user's profile without needing their own credentials. This represents a significant security risk as it enables unauthorized privilege escalation on IBM i systems. IBM has published a support advisory detailing the issue. The vulnerability is rated High severity given the unauthenticated remote exploitation potential and the ability to compromise user sessions and system integrity.

Affected products

  • IBM Application Runtime Expert (ARE) for i 1R1M0

Related CVE's

  • CVE-2026-18527

Categories

  • Enterprise Applications
  • Identity & Access