IBM i TLS Downgrade Vulnerability via Crafted Message (pre-7.7)
CVE-2026-4942 Published on July 17, 2026
IBM i is Affected by Algorithm Downgrade in Transport Layer Security []
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configuration.
Vulnerability Analysis
CVE-2026-4942 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an Algorithm Downgrade Vulnerability?
A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. When a security mechanism can be forced to downgrade to use a less secure algorithm, this can make it easier for attackers to compromise the software by exploiting weaker algorithm. The victim might not be aware that the less secure algorithm is being used. For example, if an attacker can force a communications channel to use cleartext instead of strongly-encrypted data, then the attacker could read the channel by sniffing, instead of going through extra effort of trying to decrypt the data using brute force techniques.
CVE-2026-4942 has been classified to as an Algorithm Downgrade vulnerability or weakness.
Products Associated with CVE-2026-4942
Want to know whenever a new CVE is published for IBM I? stack.watch will email you.
Affected Versions
IBM i:- Version 7.6 is affected.
- Version 7.5 is affected.
- Version 7.4 is affected.
- Version 7.3 is affected.