CVE-2026-14866
Received Received - Intake

IBM i Access Client Solutions Certificate Authority Injection

Vulnerability report for CVE-2026-14866, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: IBM Corporation

Description

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm i_access_client_solutions From 1.1.2.0 (inc) to 1.1.9.13 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 have a flaw where an attacker can inject a rogue certificate authority into the truststore. This occurs because the truststore is publicly writeable, allowing unauthorized modification of trusted certificates.

Detection Guidance

Check if IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is installed. Inspect the truststore file permissions to see if it is publicly writeable. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow attackers to impersonate trusted entities, intercept encrypted communications, or bypass security controls. It may lead to unauthorized access to sensitive data or systems if exploited.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to personal or sensitive data, undermining encryption, and failing to protect data integrity. Organizations may face penalties for non-compliance with GDPR, HIPAA, or other regulations.

Mitigation Strategies

Update IBM i Access Client Solutions to a version beyond 1.1.9.13. Restrict write permissions on the truststore file to prevent unauthorized modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14866. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart