CVE-2026-18858
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
Scoring
- Severity
- LOW
- CVSS base score
- 3.3
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.10%
- CWE
- CWE-267
- Published
- 2026-09-04
- Last modified
- 2026-09-08
Affected products
- IBM i
- IBM i
Weakness type
Related vulnerabilities
- CVE-2026-81161 — Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107
- CVE-2025-36255 — DS8900F and DS8A00 Privilege Escalation
- CVE-2026-10090 — Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription
- CVE-2026-6816 — TFA Basic Plugins - Access Bypass
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows...
- CVE-2026-42406 — BIG-IP and BIG-IQ privilege escalation vulnerability
- CVE-2026-27314 — Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass
- CVE-2026-2460 — A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and...