Skip to content
Security Alerts

CVE-2026-18527: Privilege Escalation in IBM Administration Runtime Expert for i

Processing in the ARE for i GUI component allows an unauthenticated attacker to execute actions under another user's authenticated session and gain elevated privileges...

Summary

ParameterValue
CVE IDCVE-2026-18527
Alert SourceGitHub Advisory - Critical vulnerability
CVE Year2026
Publication Date2026-08-29
VendorIBM
ProductAdministration Runtime Expert (ARE) for i, version 1R1M0
CVSS Score9.9 (Critical)
EPSS ScoreNo data
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

Source: NVD / IBM PSIRT

IBM Administration Runtime Expert (ARE) for i version 1R1M0 contains a vulnerability that allows a remote attacker to gain elevated privileges. The cause lies in how the ARE GUI component processes data.

An unauthenticated attacker can exploit this to execute actions under another user’s authenticated session. In practice that means taking over administrator privileges, if an administrator is the one logged in.

The 9.9 CVSS score — very high even among critical vulnerabilities — reflects the combination of no authentication requirement, a remote attack vector, and an impact scope reaching beyond the vulnerable component itself.

ARE is an administrative tool: it deploys and verifies configuration across many IBM i systems at once. Compromising a tool that manages multiple systems has broader reach than compromising a single server.

Required Actions

  1. Apply the IBM fix per the vendor advisory (IBM Support, node 7284580).
  2. Check whether the ARE GUI interface is reachable outside the management network. An administrative tool should not be available from user segments or the internet.
  3. Review ARE logs for administrative actions that cannot be tied to a specific administrator’s session.

Who Is Affected?

The vulnerability affects IBM i systems (formerly AS/400, iSeries) with Administration Runtime Expert for i version 1R1M0 installed.

IBM i is far more present in production than its low visibility in security discussions would suggest. Core systems in banking, insurance, logistics and manufacturing still run on this platform — often for well over a decade, carrying processes nobody migrated because they run reliably.

That reliability has a flip side: IBM i systems are often excluded from the regular vulnerability management cycle, because scanners do not always recognise them correctly and security teams less frequently hold skills on the platform. If your organisation runs IBM i, it is worth verifying whether it is covered by vulnerability inventory at all.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist