IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7284580 |
|
History
Fri, 28 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system. | |
| Title | IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ]. | |
| First Time appeared |
Ibm
Ibm administration Runtime Expert For I |
|
| Weaknesses | CWE-384 | |
| CPEs | cpe:2.3:a:ibm:administration_runtime_expert_for_i:1r1m0:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm administration Runtime Expert For I |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-08-28T20:48:33.957Z
Updated: 2026-08-28T20:48:33.957Z
Reserved: 2026-07-31T19:47:47.809Z
Link: CVE-2026-18527
No data.
Status : Received
Published: 2026-08-28T22:16:46.620
Modified: 2026-08-28T22:16:46.620
Link: CVE-2026-18527
No data.