CVE-2026-18887
Received
Received - Intake
IBM i PASE Information Disclosure Vulnerability
Vulnerability report for CVE-2026-18887, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-04
Last updated on: 2026-09-04
Assigner: IBM Corporation
Description
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | ibm_i | From 7.6 (inc) |
| ibm | ibm_i | From 7.5 (inc) |
| ibm | ibm_i | From 7.4 (inc) |
| ibm | ibm_i | From 7.3 (inc) |
| ibm | ibm_i | From 7.3 (inc) to 7.6 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |