<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>I 7.3 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/i-7.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 13 Aug 2026 22:05:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/i-7.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>IBM i TOCTOU Race Condition Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-08-ibm-i-toctou/</link><pubDate>Thu, 13 Aug 2026 22:05:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-ibm-i-toctou/</guid><description>IBM i versions 7.3 through 7.6 contain a time-of-check time-of-use (TOCTOU) race condition that allows a local authenticated attacker to gain unauthorized access to sensitive files.</description><content:encoded><![CDATA[<p>IBM i (formerly OS/400) versions 7.3, 7.4, 7.5, and 7.6 are affected by a race condition vulnerability tracked as CVE-2026-16896. The flaw stems from a time-of-check time-of-use (TOCTOU) error, which is categorized under CWE-367. This vulnerability requires the attacker to have local authenticated access to the system. By leveraging this race condition, an attacker can manipulate file operations between the initial security validation and the actual file access, potentially leading to unauthorized data disclosure or unauthorized modification of protected files. This vulnerability poses a significant risk to the integrity and confidentiality of the IBM i system, as it can be leveraged for privilege escalation or unauthorized data access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a local authenticated attacker to bypass file permission controls, resulting in unauthorized access to sensitive system or user data. This could be used by malicious actors to escalate their privileges or exfiltrate restricted information. The scope of targeting covers any environment where IBM i is deployed and internal users or compromised accounts have local access to the system.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the vendor-provided patch immediately; refer to the IBM support page at <a href="https://www.ibm.com/support/pages/node/7283293">https://www.ibm.com/support/pages/node/7283293</a> for the latest PTF (Program Temporary Fix) information.</li>
<li>Audit system logs for unusual file access patterns or repeated failed attempts by local users that might indicate exploitation attempts.</li>
<li>Review user account permissions to ensure that only necessary users have local interactive access to IBM i environments.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ibm-i</category><category>cve</category><category>race-condition</category><category>privilege-escalation</category></item></channel></rss>