EXPOSURES › CVE-2026-18527
CVE-2026-18527
CRITICALAn unauthenticated remote attacker can escalate privileges on IBM i systems via the ARE GUI component.
CVE-2026-18527 allows an unauthenticated remote attacker to execute actions under another user's authenticated profile, gaining elevated privileges on the IBM i system. DIB organizations must patch this critical vulnerability immediately to prevent privilege escalation and potential system compromise. The flaw stems from improper handling in the ARE GUI component, making it exploitable without user interaction.
Shame score — A critical privilege escalation flaw in an IBM i system component allows unauthenticated remote attackers to escalate privileges without user interaction, representing a severe avoidable risk for any organization running this software.
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.