PatchDayAlert

CVE

CVE-2026-14875

0field notes · 1digest CVSS 7.3

The verdict

When IBM i Access Client Solutions is installed for all users on Windows, it uses a directory that any local user can write to. An attacker with local access can drop a malicious binary into that directory and get it executed with elevated privileges. This requires local access to the machine, so it's a privilege escalation vector, not a remote attack.

Patch urgency · Patch this week


Daily digests