CVE-2026-18858CWE-267
CVE-2026-18858
Low · published September 4, 2026
What it is
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
The record
Technical detail
- CVSS v3.1
- 3.3 · LOW
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00094 · 0.6th percentile
- Weakness
- CWE-267 · Privilege Defined With Unsafe Actions
- Published
- 2026-09-04T20:17Z
References (1)
EPSS history
Timeline