CVE-2026-18175
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L
- EPSS probability
- 0.21%
- CWE
- CWE-285
- Published
- 2026-09-04
- Last modified
- 2026-09-04
Affected products
- IBM i
- IBM i
- IBM i
- IBM i
Weakness type
Related vulnerabilities
- CVE-2026-86804 — seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
- CVE-2026-58611 — Xbox Gaming Services Elevation of Privilege Vulnerability
- CVE-2026-86277 — SourceCodester Syllabus-Aligned Learning Management & Examination System delete_exam.php authorization
- CVE-2026-86263 — sfturing hosp_order Order Cancellation OrderController.java orderRecordsService.cancelOrder authorization
- CVE-2026-86262 — sfturing hosp_order Order OrderController.java updateOrderdiseaseInfo authorization
- CVE-2026-86261 — sfturing hosp_order Order Controller OrderController.java authorization
- CVE-2026-86283 — MISP UiBeta Collection View Bypasses Event ACL, Exposing Unauthorized Event Data
- CVE-2026-86212 — Open5GS AMF/MME improper authorization