IBM i 7.x CVE-2026-18193: Remote Bypass via Addr Validation
CVE-2026-18193 Published on August 13, 2026

IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-18193 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and a small impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
LOW

Weakness Type

Improper Privilege Management

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2026-18193

Want to know whenever a new CVE is published for IBM I? stack.watch will email you.

 

Affected Versions

IBM i: