CVE-2026-1376: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-1376 is a denial-of-service vulnerability in IBM i 7.6 caused by improper allocation of resources during failed authentication connections. A remote, unauthenticated attacker can exploit this flaw to exhaust system resources and render the affected system unavailable to legitimate users. The vulnerability was published on March 17, 2026, with a patch made available from IBM shortly thereafter. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, IBM Advisory).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), meaning the IBM i 7.6 authentication subsystem does not impose adequate limits or rate controls on resource consumption during failed login attempts. An attacker can repeatedly initiate authentication connections that fail, causing the system to allocate resources for each attempt without releasing them efficiently, ultimately exhausting available resources. No privileges, user interaction, or special preconditions are required — the authentication endpoint is typically network-accessible, making the attack surface broad. No public proof-of-concept or detailed technical write-up has been identified at this time (Feedly, IBM Advisory).

Impact

Successful exploitation results in a denial-of-service condition on IBM i 7.6 systems, with high availability impact and no confidentiality or integrity impact. Legitimate users and services are prevented from accessing the affected IBM i system for the duration of the attack. Because the attack targets the authentication mechanism — a foundational, network-exposed component — the disruption can be broad and affect all services dependent on the system's availability (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting. The vulnerability has an EPSS score of approximately 0.169%, indicating a low probability of exploitation in the near term. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly).

Exploitation steps

  1. Reconnaissance: Identify IBM i 7.6 systems exposed to the network, particularly those with authentication services (e.g., Telnet, SSH, FTP, or web-based sign-on) accessible from untrusted networks using scanning tools such as Shodan or Censys.
  2. Initiate failed authentication flood: Send a high volume of authentication requests with invalid credentials to the target IBM i 7.6 system's exposed authentication service endpoint.
  3. Resource exhaustion: Each failed authentication attempt causes the system to allocate resources without adequate throttling or release, progressively consuming available memory or connection slots.
  4. Denial of service achieved: As resources are exhausted, the system becomes unable to process legitimate authentication requests or service normal user activity, resulting in a denial-of-service condition (Feedly, IBM Advisory).

Indicators of compromise

  • Network: Unusually high volume of inbound authentication connection attempts from one or more external IP addresses; repeated failed login attempts in rapid succession targeting IBM i authentication services (e.g., Telnet port 23, SSH port 22, FTP port 21).
  • Logs: IBM i system logs (e.g., QHST, QAUDJRN) showing a surge in failed authentication events (CPF2234, CPF1107, or similar messages) from a single or small set of source addresses.
  • System Performance: Abnormal resource utilization (CPU, memory, or job table saturation) correlated with spikes in failed authentication attempts; degraded response times or service unavailability on the IBM i system.

Mitigation and workarounds

IBM has released a patch for IBM i 7.6, available via the IBM support page. Administrators should apply the relevant PTF (Program Temporary Fix) as the primary remediation step (IBM Advisory). As interim workarounds prior to patching, consider implementing network-level rate limiting or connection throttling on authentication service ports, restricting access to authentication endpoints using firewall rules to trusted IP ranges, and enabling monitoring/alerting for unusual volumes of failed authentication attempts. The IBM i PTF Guide (Volume 28, Number 12) also references this fix (IT Jungle PTF Guide).

Community reactions

Coverage of CVE-2026-1376 has been limited to automated vulnerability aggregators and security news feeds, with no notable researcher commentary or significant community discussion identified. The vulnerability was noted by RedPacket Security and referenced in the IBM i PTF Guide for the week of March 23, 2026 (IT Jungle PTF Guide). IBM has not issued a public statement beyond the support advisory.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management