Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-18527 |
| Alert Source | GitHub Advisory - Critical vulnerability |
| CVE Year | 2026 |
| Publication Date | 2026-08-29 |
| Vendor | IBM |
| Product | Administration Runtime Expert (ARE) for i, version 1R1M0 |
| CVSS Score | 9.9 (Critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
Source: NVD / IBM PSIRT
IBM Administration Runtime Expert (ARE) for i version 1R1M0 contains a vulnerability that allows a remote attacker to gain elevated privileges. The cause lies in how the ARE GUI component processes data.
An unauthenticated attacker can exploit this to execute actions under another user’s authenticated session. In practice that means taking over administrator privileges, if an administrator is the one logged in.
The 9.9 CVSS score — very high even among critical vulnerabilities — reflects the combination of no authentication requirement, a remote attack vector, and an impact scope reaching beyond the vulnerable component itself.
ARE is an administrative tool: it deploys and verifies configuration across many IBM i systems at once. Compromising a tool that manages multiple systems has broader reach than compromising a single server.
Required Actions
- Apply the IBM fix per the vendor advisory (IBM Support, node 7284580).
- Check whether the ARE GUI interface is reachable outside the management network. An administrative tool should not be available from user segments or the internet.
- Review ARE logs for administrative actions that cannot be tied to a specific administrator’s session.
Who Is Affected?
The vulnerability affects IBM i systems (formerly AS/400, iSeries) with Administration Runtime Expert for i version 1R1M0 installed.
IBM i is far more present in production than its low visibility in security discussions would suggest. Core systems in banking, insurance, logistics and manufacturing still run on this platform — often for well over a decade, carrying processes nobody migrated because they run reliably.
That reliability has a flip side: IBM i systems are often excluded from the regular vulnerability management cycle, because scanners do not always recognise them correctly and security teams less frequently hold skills on the platform. If your organisation runs IBM i, it is worth verifying whether it is covered by vulnerability inventory at all.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
