CVE-2026-18887: IBM i is Affected By Sensitive Information Exposure Vulnerability in PASE []
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.
Other sources
IBM i could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i 7.6to a version that resolves this vulnerability.Fixed in 7.6Patch MJ11365 - Upgrade
Upgrade
IBM i 7.5to a version that resolves this vulnerability.Fixed in 7.5Patch MJ11364 - Upgrade
Upgrade
IBM i 7.4to a version that resolves this vulnerability.Fixed in 7.4Patch MJ11363 - Upgrade
Upgrade
IBM i 7.3to a version that resolves this vulnerability.Fixed in 7.3Patch MJ11362
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to the affected IBM i system. The issue affects IBM i versions 7.3, 7.4, 7.5, and 7.6.
What information could be exposed?
An authenticated attacker may obtain sensitive information about PASE processes that they are not permitted to access. The provided information does not indicate that integrity or availability are affected.