Arbitrary Code Execution in IBM i via Untrusted Search Path
An untrusted search path vulnerability (CVE-2026-16674) in IBM i versions 7.3 through 7.6 allows a remote authenticated attacker to achieve arbitrary code execution.
CVE search metadata
CVE search record: CVE-2026-16674. Severity: high. CVSS: 8.8. KEV: no. Product: i. Brief: Arbitrary Code Execution in IBM i via Untrusted Search Path. Brief link: https://feed.craftedsignal.io/briefs/2026-08-ibm-i-untrusted-search-path/
IBM has disclosed a security vulnerability identified as CVE-2026-16674, affecting IBM i operating system versions 7.3, 7.4, 7.5, and 7.6. The flaw is rooted in an untrusted search path mechanism (CWE-426), which may permit an attacker with authenticated remote access to execute arbitrary code with elevated privileges.
By manipulating the search path, an attacker can influence the system to load malicious binaries or libraries instead of expected legitimate resources. Because this vulnerability is triggered during the execution of system functions, it poses a significant risk to the integrity and confidentiality of the affected IBM i environments. Defenders should prioritize patching, as this vulnerability carries a CVSS 3.1 base score of 8.8, indicating high severity and potential for significant impact if exploited.
Impact
Successful exploitation of this vulnerability allows a remote authenticated attacker to execute arbitrary code on the target IBM i system. This could lead to full system compromise, data exfiltration, or unauthorized administrative control over the affected infrastructure. The vulnerability affects critical versions of the IBM i platform, impacting enterprises that rely on these systems for core business operations.
Recommendation
- Apply the relevant security patches provided by IBM for the IBM i operating system immediately.
- Review the official IBM support advisory for CVE-2026-16674 to verify the specific PTF (Program Temporary Fix) levels required for your version of IBM i.
- Audit system configurations to ensure search path environments are strictly controlled and restricted to authorized, read-only directories where possible to mitigate similar CWE-426 vectors.
Immediate actions
Review IBM support page node 7283286 to identify the required PTFs for IBM i 7.3-7.6.
Mitigations
Patch affected IBM i instances to the recommended version provided by IBM.
CVE-2026-16674