CVE-2026-13433 PUBLISHED

IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities

Assigner: ibm
Reserved: 26.06.2026 Published: 12.08.2026 Updated: 13.08.2026

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 8.3

Product Status

Vendor IBM
Product i Access Client Solutions
Versions
  • affected from 1.1.2.0 to 1.1.9.13 (incl.)

Solutions

The issues can be fixed by upgrading to version 1.1.9.14 or later.   See https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11046 7.5SJ11044 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11044 7.4SJ11045 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11045 7.3SJ11043 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11043

References

Problem Types

  • CWE-494 Download of Code Without Integrity Check CWE