CVE-2026-18071
Undergoing Analysis Undergoing Analysis - In Progress

Improper Privilege Management in IBM i

Vulnerability report for CVE-2026-18071, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: IBM Corporation

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
ibm i 7.6
ibm i 7.5
ibm i 7.4
ibm i 7.3
ibm ibm_i to 7.3 (inc)
ibm ibm_i to 7.4 (inc)
ibm ibm_i to 7.5 (inc)
ibm ibm_i to 7.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-18071 is an improper privilege management vulnerability in IBM i's HTTP Server component. It allows a local attacker to escalate privileges due to flawed access controls. Affected versions include IBM i 7.3, 7.4, 7.5, and 7.6.

Impact Analysis

This vulnerability could let a local attacker gain elevated privileges, potentially leading to unauthorized access, data manipulation, or system disruption. It impacts confidentiality, integrity, and availability of the system.

Mitigation Strategies
  • Apply the provided PTF fixes for your IBM i version: SJ11138 for 7.3, SJ11137 for 7.4, SJ11136 for 7.5, or SJ11135 for 7.6.
  • If running an unsupported IBM i version, upgrade to a supported release immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18071. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart