Description
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
Published: 2026-08-28
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Release5733-ARE PTF Number(s)PTF Download Link(s)V1R1M0 SJ11185 After applying this PTF the legacy ARE GUI is nonfunctional. https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11185

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
Title IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ].
First Time appeared Ibm
Ibm administration Runtime Expert For I
Weaknesses CWE-384
CPEs cpe:2.3:a:ibm:administration_runtime_expert_for_i:1r1m0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm administration Runtime Expert For I
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Administration Runtime Expert For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-28T20:48:33.957Z

Reserved: 2026-07-31T19:47:47.809Z

Link: CVE-2026-18527

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:46.620

Modified: 2026-08-28T22:16:46.620

Link: CVE-2026-18527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses