CVE-2026-18858 PUBLISHED

IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH []

Assigner: ibm
Reserved: 04.08.2026 Published: 04.09.2026 Updated: 04.09.2026

IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 3.3

Product Status

Vendor IBM
Product i
Versions
  • Version 7.6 is affected
  • Version 7.5 is affected

Solutions

IBM i Release5733-SC1  PTF Number(s)PTF Download Link(s)7.6SJ11404 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11404 7.5SJ11405 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11405

IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.

References

Problem Types

  • CWE-267 Privilege Defined With Unsafe Actions CWE