Junglewise Threat Intelligence

CVE-2026-18068: IBM i information disclosure in Java Secure Sockets Extension

CVE-2026-18068 · Severity: medium · CVSS 4.3 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is a server operating system used by enterprise organizations for business-critical applications. A vulnerability in its Java Secure Sockets Extension (JSSE) component allows authenticated remote attackers to read sensitive data from the system due to confusion between byte counts and element counts in protocol handling. This could expose confidential business information transmitted over TLS connections.

Technical details

The vulnerability is an information disclosure flaw (CWE-200) in IBM i's Java Secure Sockets Extension, affecting versions 7.3 through 7.6. It stems from a byte-count and element-count confusion that allows a remote, authenticated attacker without special privileges to obtain sensitive information over the network. The vulnerability requires an existing authenticated connection (PR:L) but no user interaction. An attacker can leverage this to read confidential data during TLS session handling. IBM has released security patches (PTFs) for all affected versions.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed
  • 2026-08-13: patched: PTFs released for all affected versions

References

Related threats