CVE-2026-16695 PUBLISHED

IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities

Assigner: ibm
Reserved: 23.07.2026 Published: 12.08.2026 Updated: 12.08.2026

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor IBM
Product i Access Client Solutions
Versions
  • affected from 1.1.2.0 to 1.1.9.13 (incl.)

Solutions

The issues can be fixed by upgrading to version 1.1.9.14 or later. See IBM i Access Client Solutions updates for the latest version available. Product(s)Version(s)Remediation/Fix/Instructions IBM i Access Client Solutions1.1.2.0 - 1.1.9.13There are three ways to obtain the current version of IBM i Access Client Solutions: 1) IBM i Access Client Solutions is available at Downloads. 2) IBM i Access Client Solutions can be downloaded from the general IBM i software site at Entitled Systems Support (ESS). ID: LCD8-2010-43 3) IBM i Access Client Solutions is available by applying a PTF to IBM i. IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11046https://www.ibm.com/mysupport/s/fix-information?legacy=SJ110467.5SJ11044https://www.ibm.com/mysupport/s/fix-information?legacy=SJ110447.4SJ11045https://www.ibm.com/mysupport/s/fix-information?legacy=SJ110457.3SJ11043https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11043

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE