CVE-2026-18251
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS probability
- 0.14%
- CWE
- CWE-1385
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- IBM i
- IBM i
- IBM i
- IBM i
Weakness type
Related vulnerabilities
- CVE-2025-24964 — Remote Code Execution when accessing a malicious website while Vitest API server is listening
- CVE-2024-48849 — Authentication and Authorization Issues
- CVE-2025-52882 — Claude Code IDE extensions allow websocket connections from arbitrary origins
- CVE-2023-30856 — eDEX-UI cross-site websocket hijacking vulnerability enables remote command execution
- CVE-2023-0957 — An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSW
- CVE-2023-26114 — Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes.
- CVE-2023-2848 — Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a miss
- CVE-2026-44211 — Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability