CVE-2026-18858: IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH []
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
Other sources
IBM i could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Patch SJ11404 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Patch SJ11405
Event History
Frequently Asked Questions
Who can exploit this issue?
A local authenticated attacker can exploit it. The attacker needs access to the affected IBM i system and must be using SSH.
Which IBM i releases are identified as affected?
IBM i 7.5 and IBM i 7.6 are identified as affected.
What is the potential impact?
The issue could allow access to information from a privileged file. The reported impact is limited to confidentiality; integrity and availability are not affected.