CVE-2026-18086
Analyzed Analyzed - Analysis Complete

IBM i Improper Bounds Checking Vulnerability

Vulnerability report for CVE-2026-18086, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-19

Assigner: IBM Corporation

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-19
Generated
2026-09-03
AI Q&A
2026-08-14
EPSS Evaluated
2026-09-01
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ibm i 7.3
ibm i 7.4
ibm i 7.5
ibm i 7.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in IBM i versions 7.6, 7.5, 7.4, and 7.3 allows a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking. This means the system fails to properly validate input sizes, potentially allowing attackers to overwrite memory or trigger crashes.

Detection Guidance

This vulnerability is specific to IBM i systems and requires local access to exploit. Detection may involve checking for unusual system behavior or unauthorized code execution. No specific commands are provided in the available context.

Impact Analysis

If exploited, this flaw could let an attacker run malicious code on your system or crash it, leading to data loss or unauthorized access. Since it requires local access, attackers would need prior access to the system to exploit it.

Compliance Impact

The vulnerability allows local attackers to execute arbitrary code or cause denial of service due to improper bounds checking in IBM i systems. This could potentially lead to unauthorized access or data breaches, which may impact compliance with GDPR or HIPAA if sensitive data is exposed or altered.

Mitigation Strategies

Apply IBM i PTFs or updates to address improper bounds checking. Monitor IBM i security bulletins for patches and restrict local access to reduce attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18086. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart