CVE-2026-18858
Received Received - Intake

Local Privileged File Information Disclosure in IBM i

Vulnerability report for CVE-2026-18858, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: IBM Corporation

Description

IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm ibm_i to 7.5 (inc)
ibm ibm_i to 7.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-267 A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in IBM i 7.6 and 7.5 allows a local authenticated attacker to access sensitive information from a privileged file when using SSH. It is due to an issue in OpenSSH and has a low severity rating with a CVSS base score of 3.3.

Detection Guidance

To detect this vulnerability, check if your IBM i system is running versions 7.5 or 7.6 with the 5733-SC1 feature installed. Verify if the OpenSSH component is present and if the system is missing the required PTF fixes (SJ11404 for 7.6 or SJ11405 for 7.5).

Impact Analysis

The impact is limited as it requires local authenticated access and only allows reading privileged file information. It does not permit code execution or privilege escalation, reducing the risk of significant harm.

Mitigation Strategies

Apply the provided PTF fixes immediately: SJ11404 for IBM i 7.6 or SJ11405 for IBM i 7.5. Since no workarounds are available, patching is the only mitigation method.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18858. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart