CVE-2026-14276: IBM I Access Family

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action.

Affected products

  • IBM I Access Family: from 1.1.2.0, up to and including 1.1.9.15

Published 2026-09-14. Last modified 2026-09-17.