CVE-2026-13433
8.3
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | i Access Client Solutions | 1.1.2.0 <= 1.1.9.13 | affected |
Weaknesses
- CWE-494: CWE-494 Download of Code Without Integrity Check
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.