CVE-2026-18221: IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ]
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
Other sources
IBM i could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11231 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11230 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11233 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11235 - Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch SJ11261 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch SJ11262 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch SJ11234 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11232 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11231 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11233 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch SJ11235 - Upgrade
Upgrade
IBM i Release5770-SS1to a version that resolves this vulnerability.Patch SJ11230 - Upgrade
Upgrade
IBM i Release5770-SS1to a version that resolves this vulnerability.Patch SJ11231 - Upgrade
Upgrade
IBM i Release5770-SS1to a version that resolves this vulnerability.Patch SJ11232 - Upgrade
Upgrade
IBM i Release5770-SS1to a version that resolves this vulnerability.Patch SJ11233 - Upgrade
Upgrade
IBM i Release5770-SS1to a version that resolves this vulnerability.Patch SJ11234 - Upgrade
Upgrade
IBM i Release5770-SS1to a version that resolves this vulnerability.Patch SJ11235 - Upgrade
Upgrade
IBM i Release5770-SS1to a version that resolves this vulnerability.Patch SJ11261 - Upgrade
Upgrade
IBM i Release5770-SS1to a version that resolves this vulnerability.Patch SJ11262
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation can be performed remotely over the network without prior privileges or user interaction. It is rated high complexity, so additional unspecified conditions are required.
Which systems should be prioritized for review?
Prioritize IBM i systems running versions 7.3, 7.4, 7.5, or 7.6, particularly where remote network access is possible. The issue is associated with DDM / DRDA authentication handling.
What is the potential impact of successful exploitation?
The vulnerability may allow unauthorized access. The CVSS metrics rate confidentiality, integrity, and availability impact as high.