Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-18527: IBM Application Runtime Expert for i lets attacker gain admin
CVE-2026-18527 · published 6 days ago
Summary
The IBM Application Runtime Expert for i includes a graphical interface that can be tricked by someone on the network, even without logging in. That attacker could act as another user and obtain higher privileges on your IBM i system. Apply IBM's recommended update and limit network access to the interface to protect your environment.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | administration runtime expert for i | 1R1M0 |
Original advisory text
IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
Severity
9.9
Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-384Session Fixation
Timeline
Published28 Aug 2026
Updated2 Sep 2026
First seen28 Aug 2026
Monitor software like this
Free during beta