External risk intelligence

IBM i Missing Authentication Denial of Service and Data Integrity Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-17057

IBM i is an enterprise operating system typically deployed within internal data centers or private networks. While the vulnerability is remotely reachable, these systems are rarely exposed directly to the public internet by design, making widespread public-facing deployment uncommon, though not impossible in specific legacy or misconfigured environments.

Missing Authentication

Ibm I

7.37.47.57.6

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in IBM i systems that could allow an unauthorized remote attacker to disrupt operations and compromise data integrity due to insufficient authentication controls for essential functions. The main concern is confirming relevance and exposure.

  • Unauthenticated access can disrupt operations and data.
  • It affects core IBM i systems.
  • Verify if your IBM i systems are exposed.

Attack Path

How an attacker could exploit the issue

An attacker could reach a vulnerable IBM i system over the network. If the system exposes critical functions without requiring authentication, an attacker could interact with these functions, leading to a denial of service and potentially compromising data integrity.

  • Network access required.
  • Unauthenticated critical functions.
  • Denial of service, data integrity risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact IBM i systems by allowing unauthorized users to disrupt services and potentially alter data due to a lack of authentication for critical functions.

  • System data and integrity at risk.
  • Unauthorized access to critical functions.
  • Service disruption and data alteration.

Operational Fix

Recommended remediation, mitigation, and detection steps

IBM i system owners and platform teams are likely responsible for addressing this vulnerability. The first practical step is to identify all instances of the affected IBM i versions, confirm their network exposure and business criticality, and then assign ownership to begin remediation planning.

  • IBM i platform and system owners
  • Verify network reachability and criticality
  • Plan remediation based on risk

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is IBM i?

IBM i is a highly integrated, secure operating system designed for enterprise environments. It serves as the foundation for critical business applications, handling heavy-duty transaction processing, database management, and large-scale data operations across various industries.

What does CVE-2026-17057 mean by missing authentication?

This vulnerability, classified as CWE-306 (Missing Authentication for Critical Function), means that certain sensitive parts of the IBM i system do not check for user credentials. Because these internal safety locks are bypassed, an attacker can directly command these functions to cause service interruptions or unauthorized data changes.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending unauthorized network requests to specific, unprotected functions within the system. It is important to note that this does not stem from a user making a mistake or clicking a malicious link; it is a fundamental reachability issue where the system fails to demand identity verification for these operations.

Why should I care if my systems are internal?

While IBM i systems are generally kept in private or internal networks, Halo Surface Signal notes that internet-facing deployments are possible through misconfigurations. Even if your system is currently internal, any path allowing network reachability—whether direct or via bridged connections—could potentially be used to access these critical functions.

What should I do first to manage this risk?

Start by auditing your environment to map every active instance of IBM i 7.3 through 7.6. Once you have a clear inventory, determine which systems have network pathways that could allow outside or unauthorized access, and prioritize those for immediate oversight and security updates.

References