IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

IBM i Release5770-TC1  PTF Number(s)PTF Download Link(s)7.6SJ11371 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11371 7.5SJ11382 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11382 7.4SJ11383 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11383 7.3SJ11384 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11384 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


Workaround

No workaround given by the vendor.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper validation of FTP PORT and EPRT commands.
Title IBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T19:44:46.501Z

Reserved: 2026-08-04T16:59:54.209Z

Link: CVE-2026-18869

cve-icon Vulnrichment

Updated: 2026-09-18T19:44:40.621Z

cve-icon NVD

Status : Received

Published: 2026-09-18T20:17:10.703

Modified: 2026-09-18T20:17:10.703

Link: CVE-2026-18869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses