ibm i CVE-2026-2311 is a vulnerability in IBM I
Published on April 30, 2026

IBM i is affected by a privilege escalation vulnerability in Web Administration GUI []
IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A malicious actor could cause user-controlled code to run with administrator privilege.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-2311 can be exploited with network access, requires user interaction and user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
HIGH
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2026-2311 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2026-2311

Want to know whenever a new CVE is published for IBM I? stack.watch will email you.

 

Affected Versions

IBM i: