External risk intelligence

IBM i Code Execution via Uncontrolled Search Path

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-16860

IBM i is a server operating system typically deployed within protected internal enterprise network environments. While it supports network services, it is rarely exposed directly to the public internet, and the requirement for authenticated access further limits the likelihood of public internet reachability in common deployments.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in IBM i systems that, if exploited, could allow an authenticated attacker to execute arbitrary code. The issue stems from an uncontrolled search path element within the affected technology. While the direct exposure of IBM i systems to external threats is generally considered unlikely due to typical deployment within internal networks, understanding this vulnerability is important for assessing potential internal risks.

  • Attackers could run unauthorized code.
  • Confirms internal security posture.
  • Assess internal IBM i system risk.

Attack Path

How an attacker could exploit the issue

An attacker who has already gained some level of authenticated access to an affected IBM i system could exploit this vulnerability. By manipulating a search path element, they could trick the system into executing malicious code, potentially leading to the compromise of sensitive data and system control.

  • Authenticated access is required to begin.
  • A search path element is manipulated.
  • Arbitrary code execution and system compromise are possible.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an attacker with authenticated access to IBM i systems could potentially execute arbitrary code by manipulating an uncontrolled search path element. This could impact the integrity and confidentiality of system data and service behavior.

  • System data and integrity.
  • Authenticated remote code execution.
  • Unauthorized system control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects IBM i systems and requires an authenticated attacker to exploit. Initial triage should focus on identifying all instances of the affected IBM i versions within your environment. Once identified, confirm the business criticality and reachability of each system to prioritize remediation efforts. Ownership will likely fall to the infrastructure or platform teams managing these core systems, with coordination from the security team for exposure assessment and vendor management for any potential vendor-provided guidance or patches.

  • Infrastructure and platform teams own remediation.
  • Verify system reachability and business criticality.
  • Plan and coordinate system updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is IBM i?

IBM i is a secure, highly integrated operating system designed for business environments. It acts as the core platform for enterprise applications, database management, and transaction processing. Organizations rely on it to handle large-scale business data and critical workloads across various industries. It is built to support long-term stability for complex server infrastructures.

How does an uncontrolled search path lead to CVE-2026-16860?

This vulnerability, classified as CWE-427, occurs when the system looks for a resource in an insecure or unspecified location. An attacker can influence this search path to point the system toward their own malicious files. By tricking the system into executing these unauthorized files instead of the intended ones, the attacker achieves arbitrary code execution.

Do I need to worry if I have no authenticated users?

The vulnerability requires an attacker to already possess authenticated access to the IBM i system. Therefore, an attacker cannot trigger this bug simply by having network access alone; they must first bypass or hold valid credentials. This means the flaw cannot be triggered by unauthenticated visitors or anonymous automated scanning.

Is my IBM i system at risk from the internet?

According to Halo Surface Signal, it is unlikely. IBM i is generally deployed within protected internal networks rather than being exposed to the public internet. Because the vulnerability requires an attacker to already be authenticated, the combination of internal placement and credential requirements significantly limits the potential for remote exploitation from the outside.

When should I prioritize addressing this vulnerability?

You should prioritize this by first identifying all active instances of the affected IBM i versions (7.3 through 7.6) in your environment. Evaluate the business criticality and reachability of these systems to guide your timeline. Your infrastructure and platform teams should lead the effort to verify the systems and coordinate with the vendor to plan necessary updates or security configurations.

References