CVE-2026-18175
massUnauthenticated database transaction manipulation in IBM i DDM dispatcher (CWE-285)
CVE-2026-18175 is an improper authorization flaw (CWE-285) in the DDM target dispatcher of IBM i, the operating system that runs on IBM Power Systems. The DDM (Distributed Data Management) component handles remote database requests such as DRDA connections, and a remote, unauthenticated attacker who can reach that listener can send crafted DDM requests that bypass the dispatcher's authorization checks. The documented impact is integrity-only: the attacker can manipulate database transactions without obtaining read access to the data or disrupting availability. All four currently supported IBM i releases — 7.6, 7.5, 7.4, and 7.3 — are in scope, so essentially the entire supported IBM i installed base is affected. No proof-of-concept or in-the-wild exploitation is known; EPSS currently assigns only a 0.2% probability of exploitation within the next 30 days.
What to do: Apply IBM's corrective PTFs for the DDM target dispatcher to every IBM i 7.3, 7.4, 7.5, and 7.6 partition once IBM publishes them (check IBM Fix Central and the IBM PSIRT bulletin for this CVE). Until patched, restrict the DDM/DRDA TCP/IP server (typically ports 446 and 448) to trusted hosts and audit whether any partition's DDM listener is reachable from untrusted networks or the internet.
| IBM i | 7.6, 7.5, 7.4, 7.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
- Vendors
- ibm
- Products
- i
- Weakness
- CWE-285
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.