Skip to content
COOEY

EXPOSURES › CVE-2026-18527

CVE-2026-18527

CRITICAL
DETAIL
SourceNVD · cve Published2026-08-28 CVSS9.9 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-18527 ↗
⚡ RCE SHAME 78/100 unpatchedexploited-in-wildrceprivilege-escalation

An unauthenticated remote attacker can escalate privileges on IBM i systems via the ARE GUI component.

CVE-2026-18527 allows an unauthenticated remote attacker to execute actions under another user's authenticated profile, gaining elevated privileges on the IBM i system. DIB organizations must patch this critical vulnerability immediately to prevent privilege escalation and potential system compromise. The flaw stems from improper handling in the ARE GUI component, making it exploitable without user interaction.

Shame score — A critical privilege escalation flaw in an IBM i system component allows unauthenticated remote attackers to escalate privileges without user interaction, representing a severe avoidable risk for any organization running this software.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.