Skip to content
IBMCVE-2026-18527

IBM Administration Runtime Expert for i: privilege escalation

Critical9.9CVE-2026-18527 · Published Aug 28, 2026 · updated Aug 31, 2026

IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.

IBM advisory

Affected versions

PackageAffectedFixed in
Administration Runtime Expert for i
Product
<= 1R1M0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-384

More IBM advisories

All IBM
Advisory
IBM Concert: SQL injection
Critical9.1Aug 28
IBM Cloud Pak for Data System: denial of service
Medium6.2Aug 28
IBM Langflow OSS: path traversal
High7.5Aug 28
IBM Langflow OSS: information disclosure
High8.2Aug 28
IBM Langflow OSS: remote code execution
Critical9.8Aug 28
IBM Langflow OSS: improper authorization
Medium6.4Aug 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.