CVE-2026-7770 Details
Description
IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.
A remote code execution vulnerability exists in the IBM i Access Client Solutions (ACS) within the IBM i Access Family, specifically in versions 1.1.5.0 through 1.1.9.12. The vulnerability arises when ACS is configured to accept requests from IBM i Navigator.
Users can upgrade to version 1.1.9.13 or later to address this vulnerability. The latest version of IBM i Access Client Solutions can be downloaded from the IBM i software site via Entitled Systems Support (ESS), or by applying a PTF to IBM i. For IBM i releases 7.6, 7.5, 7.4, and 7.3, specific PTF numbers and download links are available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7274214 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm i access client solutions | >= 1.1.5.0, < 1.1.9.13 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 26, 2026 | Initial Analysis | [email protected] |
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | New CVE Received | [email protected] |