← Vulnerability feed

Vulnerability record · CVE-2026-17069 · published 13 August 2026

CVE-2026-17069: Ibm i cross-site request forgery vulnerability

Ibm · I

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.

7.3 CVSS 3.1 High EPSS 0.22% · top 88.5% CWE-352 · Cross-site request forgery
7.3CVSS 3.1 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Aug 2026Last modified by NVD

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-17069 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-18193Ibm i improper privilege management vulnerabilityIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.EPSS 0.45%9.9CVE-2026-18249Ibm i improper privilege management vulnerabilityIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from…EPSS 0.39%9.9CVE-2026-17276Ibm i improper privilege management vulnerabilityIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high…EPSS 0.47%9.9CVE-2026-16860Ibm i uncontrolled search path element vulnerabilityIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.EPSS 0.75%9.8CVE-2026-18221Ibm i improper authentication vulnerabilityIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication p…EPSS 0.34%9.8CVE-2026-17206Ibm i out-of-bounds write vulnerabilityIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.EPSS 0.67%9.8CVE-2026-16961Ibm i sql injection vulnerabilityIBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker …EPSS 0.45%9.8CVE-2026-16867Ibm i improper authentication vulnerabilityIBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper au…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2026-17069), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.