Back Redpacketsecurity CVE Alert: CVE-2026-84414 – IBM
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
**Risk verdict:** High risk to affected hosts; expedite remediation, but exploitation urgency cannot be confirmed because KEV and SSVC status were not provided.
**Why this matters:** An authenticated local user may be able to alter ownership of files, potentially undermining controls protecting sensitive data or system components. Depending on the files affected and how services run, this could support privilege escalation, data tampering or disruption; there is no supplied evidence to judge whether exploitation is widespread.
**Most likely attack path:** An attacker first obtains a low-privilege local account, possibly through another compromise or misuse of legitimate access, then triggers the vulnerable file-handling path without further user interaction. The impact is confined to the same host, but changes to files used by privileged services could create a route to greater control on that system.
**Who is most exposed:** Organisations running business-critical midrange systems with multiple local accounts, application workloads or network-authentication services warrant review, especially where access is shared.
Alert on unexpected file ownership changes, particularly for sensitive or service-used paths.
Review audit records for ownership changes by low-privilege accounts.
Correlate file changes with unusual authentication activity or subsequent privileged processes.
Compare ownership of critical files against a trusted baseline.
Mitigation and prioritisation:
Apply the vendor’s release-specific corrective PTF promptly; verify installation on every affected host.
Test the PTF in a representative environment and follow normal change controls.
Until patched, restrict local access and review accounts with unnecessary access.
Check for unexplained ownership changes and investigate before restoring known-good ownership.
EPSS, PoC and exploitation-status data were not supplied; obtain these to refine urgency and confirm whether active exploitation is indicated.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
