CVE-2026-18527CWE-384

CVE-2026-18527

Critical · published August 29, 2026

CVSS v3.1
9.9
EPSS
0%
Percentile
20.8
In the wild
Unconfirmed
What it is

IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.

The record
Technical detail
CVSS v3.1
9.9 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00286 · 20.8th percentile
Weakness
CWE-384 · Session Fixation
Published
2026-08-29T02:16Z
References (1)
EPSS history
Timeline
  • 30 AUG 16:16Z
    EPSS moved — → 0%
    epss
  • 28 AUG 20:48Z
    IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].
    cvelistv5