CVE-2026-84414
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
- Published Sep 29, 2026
- CVSS 7.8 high
- 0.1% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- IBM security advisory (AV26-997) Canadian Centre for Cyber Security ·