{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/i-access-client-solutions-1.1.2.0-1.1.9.13/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-13094"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["i Access Client Solutions","i Access Client Solutions (1.1.2.0-1.1.9.13)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","local-privilege-escalation","windows"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM i Access Client Solutions (ACS) versions 1.1.2.0 through 1.1.9.13 are vulnerable to arbitrary code execution on Windows systems when installed for all users. The vulnerability stems from insecure write permissions applied to a configuration file during installation. A local attacker with authenticated access can modify this file to inject malicious code or arguments, which are subsequently executed with the privileges of the user running the application. This vulnerability is assigned CVE-2026-13094 and carries a CVSS score of 7.8 (High). Impacted organizations should apply the updates provided by IBM to remediate the insecure configuration file permissions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes local access to a Windows system where IBM i Access Client Solutions is installed for all users.\u003c/li\u003e\n\u003cli\u003eAttacker enumerates the ACS installation directory and subdirectories to locate configuration files.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a configuration file with weak discretionary access control lists (DACLs) permitting non-administrative write access.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the configuration file to include malicious commands or point to a malicious library/script.\u003c/li\u003e\n\u003cli\u003eAn authorized user (or elevated service) launches the IBM i Access Client Solutions application.\u003c/li\u003e\n\u003cli\u003eThe application parses the malicious configuration file during initialization.\u003c/li\u003e\n\u003cli\u003eThe application executes the injected code or triggers the malicious path during runtime.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved: execution of arbitrary code in the context of the user running the application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local attacker to execute arbitrary code on the affected Windows system. This can lead to local privilege escalation, persistence, or data theft, depending on the privileges of the user executing the application. The vulnerability affects all deployments of IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 installed in a multi-user context.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate IBM i Access Client Solutions to a patched version as advised by the vendor in the official support bulletin (CVE-2026-13094).\u003c/li\u003e\n\u003cli\u003eUse File Integrity Monitoring (FIM) or audit logs to detect unauthorized modifications to application configuration files in 'C:\\ProgramData' or 'C:\\Program Files'.\u003c/li\u003e\n\u003cli\u003eReview the permissions of the configuration files for IBM software to ensure they are restricted to Administrators and SYSTEM accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T22:52:58Z","date_published":"2026-08-12T22:52:22Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ibm-i-access-code-execution/","summary":"IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 contain a local arbitrary code execution vulnerability on Windows due to insecure file permissions on a configuration file.","title":"Arbitrary Code Execution in IBM i Access Client Solutions","url":"https://feed.craftedsignal.io/briefs/2026-08-ibm-i-access-code-execution/"}],"language":"en","title":"CraftedSignal Threat Feed - I Access Client Solutions (1.1.2.0-1.1.9.13)","version":"https://jsonfeed.org/version/1.1"}