CVE-2026-13433
Received Received - Intake

IBM i Access Client Solutions Code Execution Vulnerability

Vulnerability report for CVE-2026-13433, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: IBM Corporation

Description

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm i_access_client_solutions From 1.1.2.0 (inc) to 1.1.9.13 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-494 The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM i Access Client Solutions (ACS) versions 1.1.2.0 through 1.1.9.13 have a flaw where they download unverified product code during updates from an IBM i system. This allows an attacker to replace the update with malicious code that runs on the user's workstation when installed.

Detection Guidance

To detect this vulnerability, check if IBM i Access Client Solutions (ACS) is installed and verify its version. Look for ACS installations in default directories like C:\Program Files\IBM\Client Access or /opt/ibm/acs. Check the version via the ACS application interface or by examining installed files. Ensure no unauthorized updates or suspicious network connections to IBM i hosts are present.

Impact Analysis

This vulnerability could allow an attacker to execute arbitrary code on your workstation by tricking ACS into installing compromised updates. This may lead to data theft, system compromise, or further network infiltration depending on your workstation's access privileges.

Mitigation Strategies

Immediately update IBM i Access Client Solutions to the latest version beyond 1.1.9.13. Disable automatic updates from IBM i hosts if not required. Monitor network traffic for suspicious connections to IBM i systems. Remove or restrict access to ACS if unused. Apply network segmentation to limit ACS update traffic.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13433. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart