What is CVE-2026-18099?
This critical vulnerability allows a remote authenticated attacker to execute arbitrary script code on IBM i operating systems due to improper neutralization of user-controlled input. Affected versions include 7.3, 7.4, 7.5, and 7.6; immediate security patches from the vendor must be applied and input validation should be strengthened.
Azərbaycanca: Bu kritik boşluq, uzaqdan autentifikasiya olunmuş hücumçuya IBM i əməliyyat sistemində istifadəçi tərəfindən daxil edilən məlumatların düzgün neytrallaşdırılmaması səbəbindən ixtiyari skript kodunu icra etməyə imkan verir. Təsirə məruz qalan versiyalar 7.3, 7.4, 7.5 və 7.6-dır, dərhal təchizatçının təqdim etdiyi təhlükəsizlik yeniləmələri tətbiq edilməli və giriş yoxlamaları gücləndirilməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: IBM
FAQ2
Does an attacker need to be authenticated to exploit this vulnerability on the IBM i system?
Yes, this vulnerability allows a remote authenticated attacker to execute arbitrary script code on the affected system.
Which versions of the IBM i operating system are affected by CVE-2026-18099?
The affected versions are IBM i 7.3, 7.4, 7.5, and 7.6.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.