IBM disclosed a CVSS 9.9 flaw in Administration Runtime Expert for i 1R1M0 that, according to the vendor's description, could allow a remote attacker to act under another user's authenticated profile and gain elevated privileges on the IBM i system. IBM characterizes the attacker as unauthenticated, though its own CVSS vector assigns Privileges Required: Low; see below.
What Is It
CVE-2026-18527 is a session fixation vulnerability (CWE-384) in the Administration Runtime Expert for i GUI component; referred to as the "ARE GUI component" in IBM's advisory text. According to that advisory, improper handling in ARE GUI component processing allows a remote attacker to execute actions under another user's authenticated profile, resulting in elevated privileges on the underlying IBM i system.
IBM PSIRT scored the issue CVSS 3.1 base 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network attack vector, low complexity, no user interaction, and a scope change with high confidentiality, integrity, and availability impact.
Why It Matters
The scope-change component is what pushes this to 9.9: a successful attack does not stay inside the ARE web component. IBM's description states the attacker gains elevated privileges on the IBM i system itself, meaning the compromise crosses from the administration tooling into the host platform. ARE is administration software, so the profiles it handles tend to be privileged ones.
The prose and the vector disagree on the precondition: IBM's description characterizes the attacker as unauthenticated, while the CVSS vector assigns Privileges Required: Low. Neither the NVD record nor the advisory resolves the discrepancy, so defenders should plan against the more conservative reading, that no valid credentials are required, while recognizing that the scored vector implies at least low-privilege access.
No supplied source confirms active exploitation in the wild.
What's Vulnerable
- Vendor: IBM
- Product: Administration Runtime Expert for i
- Affected version: 1R1M0 (
cpe:2.3:a:ibm:administration_runtime_expert_for_i:1r1m0)
No other products or versions are listed as affected in the supplied NVD record.
Patch Status
IBM has published a support advisory for this issue at IBM support node 7284580. The supplied NVD record is in Received status as of its 2026-08-28 publication and does not enumerate specific fix levels or PTF identifiers, so administrators should consult IBM's advisory directly for remediation guidance applicable to their release.
Sources
- NVD, CVE-2026-18527: https://nvd.nist.gov/vuln/detail/CVE-2026-18527
- IBM Support Advisory ([email protected]): https://www.ibm.com/support/pages/node/7284580