Improper Authorization Vulnerability in IBM i Database Transaction Handling
CVE-2026-18175

8.1HIGH

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-18175?

A vulnerability in IBM i versions 7.3, 7.4, 7.5, and 7.6 may allow a remote attacker to manipulate database transactions. This issue arises from improper authorization in the Distributed Data Management (DDM) target dispatcher, potentially facilitating unauthorized access to sensitive information or the execution of malicious commands. Organizations using affected versions should promptly apply the appropriate patches to mitigate this risk.

Affected Version(s)

i 7.6

i 7.5

i 7.4

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.