IBMCVE-2026-18527
IBM Administration Runtime Expert for i: privilege escalation
Critical9.9CVE-2026-18527 · Published Aug 28, 2026 · updated Aug 31, 2026
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Administration Runtime Expert for i Product | <= 1R1M0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-384
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | IBM Concert: SQL injection | Critical9.1 | No fix yet |
| Aug 28 | IBM Cloud Pak for Data System: denial of service | Medium6.2 | No fix yet |
| Aug 28 | IBM Langflow OSS: path traversal | High7.5 | No fix yet |
| Aug 28 | IBM Langflow OSS: information disclosure | High8.2 | No fix yet |
| Aug 28 | IBM Langflow OSS: remote code execution | Critical9.8 | No fix yet |
| Aug 28 | IBM Langflow OSS: improper authorization | Medium6.4 | No fix yet |