CVE-2026-13094 PUBLISHED

IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities

Assigner: ibm
Reserved: 23.06.2026 Published: 12.08.2026 Updated: 12.08.2026

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor IBM
Product i Access Client Solutions
Versions
  • affected from 1.1.2.0 to 1.1.9.13 (incl.)

Solutions

The issues can be fixed by upgrading to version 1.1.9.14 or later.   See https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11046 7.5SJ11044 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11044 7.4SJ11045 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11045 7.3SJ11043 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11043

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE