CVE-2026-18221
largeImproper Authentication in IBM i 7.3–7.6 Allows Unauthorized Remote Access
IBM i releases 7.3, 7.4, 7.5, and 7.6 fail to properly validate client-supplied authentication parameters (CWE-287), allowing a remote attacker to gain unauthorized access to the system. The flaw is triggered over the network by sending crafted authentication parameters to an affected IBM i service, with no privileges or user interaction required per the CVSS vector. An attacker who successfully bypasses authentication gains unauthorized access with potentially high confidentiality, integrity, and availability impact (CVSS 3.1 score 9.8, critical). All organizations running IBM i on releases 7.3 through 7.6 are potentially affected, particularly where those systems are reachable from untrusted networks. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS currently estimates only a 0.3% probability of exploitation in the next 30 days, so no confirmed in-the-wild exploitation is known.
What to do: Deploy the IBM-provided fixes/PTFs for this vulnerability on IBM i 7.3, 7.4, 7.5, and 7.6 as published in IBM's security bulletin. In the interim, verify whether the affected IBM i systems accept authentication traffic from untrusted networks and restrict access with firewalls or network segmentation. Since no exploit is publicly known, prioritize internet-facing and partner-facing IBM i systems for remediation first.
| IBM i | 7.3, 7.4, 7.5, 7.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
- Vendors
- ibm
- Products
- i
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.