CVE-2026-16987

Summary

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.

Affected Software

VendorProductVersion RangeStatus
IBMi7.6affected
IBMi7.5affected
IBMi7.4affected
IBMi7.3affected

Weaknesses

  • CWE-73: CWE-73 External Control of File Name or Path

References