VDB

CVE-2026-16987

CVE-2026-16987 PUBLISHED CVSS 8.8 HIGH

Reported by ibm · Published August 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.

Risk Scores

CVSS 3.1
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
IBMi7.6, 7.5, 7.4
IBMi7.6, 7.5, 7.4

Timeline

  • Aug 11, 2026 CVE Published
  • Aug 20, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score

References

  • vendor-advisorypatch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›