VDB
CVE-2026-16987
CVE-2026-16987
PUBLISHED
CVSS 8.8 HIGH
Reported by ibm · Published August 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| IBM | i | 7.6, 7.5, 7.4 |
| IBM | i | 7.6, 7.5, 7.4 |
Timeline
- Aug 11, 2026 CVE Published
- Aug 20, 2026 Security Advisory
- Aug 24, 2026 EPSS Score