CVE-2026-18073: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
Other sources
IBM i could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Patch SJ11305 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Patch SJ11306 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Patch SJ11307 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Patch SJ11308
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires local authenticated access to an affected IBM i system. The provided data does not indicate that unauthenticated remote attackers can exploit it.
What capabilities could an attacker gain through exploitation?
An attacker could inject parameters into a CL command because special elements are not properly neutralized. The stated impact includes low confidentiality and low integrity impact, with no availability impact.
Which IBM i releases are identified as affected?
The affected releases listed are IBM i 7.6, 7.5, 7.4, and 7.3. The issue is associated with the IBM i Debug Server.