CVE-2026-18193: IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
Other sources
IBM i could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6 (Release 5770-JV1)to a version that resolves this vulnerability.Patch SJ11037 - Upgrade
Upgrade
IBM i 7.6 (Release 5770-JV1)to a version that resolves this vulnerability.Patch SJ11013 - Upgrade
Upgrade
IBM i 7.6 (Release 5770-JV1)to a version that resolves this vulnerability.Patch SJ11014 - Upgrade
Upgrade
IBM i 7.6 (Release 5770-JV1)to a version that resolves this vulnerability.Patch SJ11041 - Upgrade
Upgrade
IBM i 7.6 (Release 5770-JV1)to a version that resolves this vulnerability.Patch SJ11042 - Upgrade
Upgrade
IBM i 7.6 (Release 5770-JV1)to a version that resolves this vulnerability.Patch SJ11063 - Upgrade
Upgrade
IBM i 7.6 (Release 5770-JV1)to a version that resolves this vulnerability.Patch SJ11064 - Upgrade
Upgrade
IBM i 7.6 (Release 5770-JV1)to a version that resolves this vulnerability.Patch SJ11065 - Upgrade
Upgrade
IBM i 7.6 (Release 5770-JV1)to a version that resolves this vulnerability.Patch SJ11066 - Upgrade
Upgrade
IBM i 7.6 (Release 5770-JV1)to a version that resolves this vulnerability.Patch SJ11078 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Patch SJ10990 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Patch SJ11079 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Patch SJ11080 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Patch SJ11016 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Patch SJ11081 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Patch SJ11040
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18193?
The severity of CVE-2026-18193 is rated as high with a score of 8.9.
How do I fix CVE-2026-18193?
To fix CVE-2026-18193, apply the latest security updates provided by IBM for the IBM Java SDK and IBM Java Runtime.
What systems are affected by CVE-2026-18193?
CVE-2026-18193 affects IBM i versions 7.6, 7.5, 7.4, and 7.3.
What vulnerability does CVE-2026-18193 address?
CVE-2026-18193 addresses a vulnerability that allows remote attackers to bypass security restrictions due to improper validation of user-controlled addresses.
Can CVE-2026-18193 be exploited remotely?
Yes, CVE-2026-18193 can be exploited remotely, allowing attackers to bypass security measures.