Junglewise Threat Intelligence

CVE-2026-18076: IBM i memory leak in Debug Server denial of service

CVE-2026-18076 · Severity: medium · CVSS 4.3 · Published 2026-09-04

Executive brief

IBM i is an enterprise operating system used to run mission-critical business applications. The Debug Server component contains a memory leak that allows authenticated remote attackers to exhaust system memory and cause service outages, impacting availability of dependent business operations.

Technical details

IBM i versions 7.6, 7.5, 7.4, and 7.3 contain a memory leak vulnerability (CWE-401: Missing Release of Memory after Effective Lifetime) in the Debug Server component. An authenticated attacker with remote network access can trigger the memory leak condition, causing the affected system to consume memory until resources are exhausted, resulting in denial of service. Authentication is required to exploit this vulnerability. IBM has released PTFs (Program Temporary Fixes) for all affected versions: SJ11305 (7.6), SJ11306 (7.5), SJ11307 (7.4), and SJ11308 (7.3).

Affected products

  • IBM i 7.6 7.6
  • IBM i 7.5 7.5
  • IBM i 7.4 7.4
  • IBM i 7.3 7.3

Timeline

  • 2026-09-04: disclosed

References

Related threats