VDB

GCVE-110-NCSC-2026-301

GCVE-110-NCSC-2026-301
Advisory PublishedCVSS 8.2/10
Vulnetix · Advisory published August 14, 2026
IBM i versions 7.3 through 7.6 contain a vulnerability in privilege management that allows remote authenticated attackers to escalate privileges unauthorizedly.

Weaknesses (CWE)

CWE-427Uncontrolled Search Path ElementCWE-125Out-of-bounds ReadCWE-787Out-of-bounds WriteCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-367Time-of-check Time-of-use (TOCTOU) Race ConditionCWE-73External Control of File Name or PathCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-770Allocation of Resources Without Limits or ThrottlingCWE-250Execution with Unnecessary Privileges

Risk Scores

CVSS 3.1
8.2/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
IBMvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

867 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›