CVE-2026-18658
moderateUnauthenticated SQL Injection to RCE in IBM Operational Decision Manager
IBM Operational Decision Manager (ODM), an enterprise business-rules platform, contains a SQL injection vulnerability (CWE-89) in a component reachable over the network. An unauthenticated attacker can submit crafted input that is incorporated into SQL statements, gaining the ability to execute arbitrary SQL against the product's backend database. By leveraging database functionality to write files, the attacker can plant a web shell in the application web root and achieve remote code execution on the affected server. The flaw affects the listed ODM releases 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, 9.5.0.0, 9.5.0.1, and 9.6.0.0, so any deployment running one of these versions is exposed. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time, and EPSS estimates only a 0.4% chance of exploitation within the next 30 days.
What to do: Apply the vendor fix for CVE-2026-18658 by upgrading each affected ODM release to the fixed or interim release specified in IBM's security bulletin. Until patched, restrict network access to the ODM application tier to trusted networks and users, since exploitation requires no authentication. As a compromise check, look for unexpected files or web shells in the application web root and review database logs for unusual or unexpected SQL statements.
| IBM Operational Decision Manager | 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, 9.5.0.0, 9.5.0.1, 9.6.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.