CVE-2026-17029
Awaiting Analysis Awaiting Analysis - Queue

IBM i Local Code Execution via Out-of-Bounds Write

Vulnerability report for CVE-2026-17029, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: IBM Corporation

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
ibm i 7.6
ibm i 7.5
ibm i 7.4
ibm i 7.3
ibm ibm_i From 7.3 (inc) to 7.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-17029 is a vulnerability in IBM i's Java Secure Sockets Extension (JSSE) that allows a local attacker to execute arbitrary code due to an out-of-bounds write. This flaw is classified under CWE-787 (Out-of-bounds Write) and affects IBM i versions 7.3 through 7.6.

Detection Guidance

Detection of CVE-2026-17029 requires checking for the presence of vulnerable IBM i versions and applying IBM's PTFs. No direct commands are provided in the resources, but you should verify your IBM i version and apply the recommended PTFs from IBM's support page.

Impact Analysis

A local attacker could exploit this vulnerability to execute arbitrary code on the affected IBM i system. This could lead to unauthorized access, data breaches, or system compromise, depending on the attacker's goals and the system's configuration.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or other standards as it involves a local privilege escalation issue in IBM i's JSSE component. Compliance impacts would depend on how the vulnerability is exploited in a specific environment rather than the vulnerability itself.

Mitigation Strategies

Apply the provided PTFs (Program Temporary Fixes) from IBM to remediate the issue. Upgrade to supported IBM i versions if running unsupported software. No workarounds are available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17029. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart