Junglewise Threat Intelligence

CVE-2026-18098: IBM i XML injection remote attack

CVE-2026-18098 · Severity: high · CVSS 8.1 · Published 2026-08-12

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise operating system used to run critical business applications and databases. A remote authenticated attacker can exploit an XML injection flaw to read sensitive system information and potentially alter system behavior, compromising the integrity of business-critical operations.

Technical details

CVE-2026-18098 is an XML injection vulnerability in IBM i versions 7.3 through 7.6. The vulnerability requires remote network access and valid authentication credentials. By injecting malicious XML payloads through an unspecified input vector, an attacker can extract sensitive information from the system and potentially modify system state or execute unintended operations. The vulnerability affects the Navigator for i component and related system services. Patches are expected to be available from IBM; users should review IBM's security bulletin for specific remediation guidance.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-12: disclosed

References

Related threats