# CVE-2026-18658

## Summary

- **CVE ID:** CVE-2026-18658
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-89
- **Published:** Sep 4, 2026
- **Last Modified:** Sep 11, 2026

## Description

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.

## Affected Products

- IBM — Operational Decision Manager (9.6.0.0)
- IBM — Operational Decision Manager (9.5.0.0)
- IBM — Operational Decision Manager (8.11.1.0)
- IBM — Operational Decision Manager (8.11.0.1)
- IBM — Operational Decision Manager (8.12.0.1)
- IBM — Operational Decision Manager (9.5.0.1)
- IBM — Operational Decision Manager (9.0.0.1)

## References

- [CNA](https://www.ibm.com/support/pages/node/7286196)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.43%
- **EPSS Percentile:** 36.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._