{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/i-7.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-16896"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["i 7.3","i 7.4","i 7.5","i 7.6"],"_cs_severities":["high"],"_cs_tags":["ibm-i","cve","race-condition","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM i (formerly OS/400) versions 7.3, 7.4, 7.5, and 7.6 are affected by a race condition vulnerability tracked as CVE-2026-16896. The flaw stems from a time-of-check time-of-use (TOCTOU) error, which is categorized under CWE-367. This vulnerability requires the attacker to have local authenticated access to the system. By leveraging this race condition, an attacker can manipulate file operations between the initial security validation and the actual file access, potentially leading to unauthorized data disclosure or unauthorized modification of protected files. This vulnerability poses a significant risk to the integrity and confidentiality of the IBM i system, as it can be leveraged for privilege escalation or unauthorized data access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local authenticated attacker to bypass file permission controls, resulting in unauthorized access to sensitive system or user data. This could be used by malicious actors to escalate their privileges or exfiltrate restricted information. The scope of targeting covers any environment where IBM i is deployed and internal users or compromised accounts have local access to the system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the vendor-provided patch immediately; refer to the IBM support page at \u003ca href=\"https://www.ibm.com/support/pages/node/7283293\"\u003ehttps://www.ibm.com/support/pages/node/7283293\u003c/a\u003e for the latest PTF (Program Temporary Fix) information.\u003c/li\u003e\n\u003cli\u003eAudit system logs for unusual file access patterns or repeated failed attempts by local users that might indicate exploitation attempts.\u003c/li\u003e\n\u003cli\u003eReview user account permissions to ensure that only necessary users have local interactive access to IBM i environments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T22:05:55Z","date_published":"2026-08-13T22:05:55Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ibm-i-toctou/","summary":"IBM i versions 7.3 through 7.6 contain a time-of-check time-of-use (TOCTOU) race condition that allows a local authenticated attacker to gain unauthorized access to sensitive files.","title":"IBM i TOCTOU Race Condition Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-ibm-i-toctou/"}],"language":"en","title":"CraftedSignal Threat Feed - I 7.6","version":"https://jsonfeed.org/version/1.1"}