Skip to content
Threat Feed
high advisory

Arbitrary Code Execution in IBM i via Untrusted Search Path

An untrusted search path vulnerability (CVE-2026-16674) in IBM i versions 7.3 through 7.6 allows a remote authenticated attacker to achieve arbitrary code execution.

CVE search metadata

CVE search record: CVE-2026-16674. Severity: high. CVSS: 8.8. KEV: no. Product: i. Brief: Arbitrary Code Execution in IBM i via Untrusted Search Path. Brief link: https://feed.craftedsignal.io/briefs/2026-08-ibm-i-untrusted-search-path/

IBM has disclosed a security vulnerability identified as CVE-2026-16674, affecting IBM i operating system versions 7.3, 7.4, 7.5, and 7.6. The flaw is rooted in an untrusted search path mechanism (CWE-426), which may permit an attacker with authenticated remote access to execute arbitrary code with elevated privileges.

By manipulating the search path, an attacker can influence the system to load malicious binaries or libraries instead of expected legitimate resources. Because this vulnerability is triggered during the execution of system functions, it poses a significant risk to the integrity and confidentiality of the affected IBM i environments. Defenders should prioritize patching, as this vulnerability carries a CVSS 3.1 base score of 8.8, indicating high severity and potential for significant impact if exploited.

Impact

Successful exploitation of this vulnerability allows a remote authenticated attacker to execute arbitrary code on the target IBM i system. This could lead to full system compromise, data exfiltration, or unauthorized administrative control over the affected infrastructure. The vulnerability affects critical versions of the IBM i platform, impacting enterprises that rely on these systems for core business operations.

Recommendation

  • Apply the relevant security patches provided by IBM for the IBM i operating system immediately.
  • Review the official IBM support advisory for CVE-2026-16674 to verify the specific PTF (Program Temporary Fix) levels required for your version of IBM i.
  • Audit system configurations to ensure search path environments are strictly controlled and restricted to authorized, read-only directories where possible to mitigate similar CWE-426 vectors.

Immediate actions

Review IBM support page node 7283286 to identify the required PTFs for IBM i 7.3-7.6.

IT Operations 48h

Mitigations

Patch affected IBM i instances to the recommended version provided by IBM.

immediate IT Operations

CVE-2026-16674