CVE-2026-2311
Received Received - Intake
IBM i Web Administration Privilege Escalation Vulnerability

Publication date: 2026-04-30

Last updated on: 2026-05-01

Assigner: IBM Corporation

Description
IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check. Β A malicious actor could cause user-controlled code to run with administrator privilege.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-30
Last Modified
2026-05-01
Generated
2026-06-16
AI Q&A
2026-05-01
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 5 associated CPEs
Vendor Product Version / Range
ibm i 7.2
ibm i 7.3
ibm i 7.4
ibm i 7.5
ibm i 7.6
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects IBM i versions 7.6, 7.5, 7.4, 7.3, and 7.2. It is caused by an invalid authorization check in the IBM i Web Administration GUI, which allows a malicious actor to escalate privileges.

Specifically, an attacker could exploit this flaw to run user-controlled code with administrator privileges.

Impact Analysis

The vulnerability can lead to privilege escalation, meaning an attacker could gain administrator-level access on the affected IBM i system.

With administrator privileges, the attacker could execute arbitrary code, potentially compromising system integrity, confidentiality, and availability.

Mitigation Strategies

To mitigate the CVE-2026-2311 vulnerability in IBM i Web Administration GUI, users should apply the relevant Program Temporary Fixes (PTFs) released by IBM for their specific IBM i versions (7.2 through 7.6).

There are no available workarounds currently, so applying the official fixes is critical.

Additionally, IBM recommends upgrading to supported versions if you are running unsupported software.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-2311. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart