Executive brief
IBM i is an enterprise operating system used to run critical business applications and databases. A remote authenticated attacker can exploit an XML injection flaw to read sensitive system information and potentially alter system behavior, compromising the integrity of business-critical operations.
Technical details
CVE-2026-18098 is an XML injection vulnerability in IBM i versions 7.3 through 7.6. The vulnerability requires remote network access and valid authentication credentials. By injecting malicious XML payloads through an unspecified input vector, an attacker can extract sensitive information from the system and potentially modify system state or execute unintended operations. The vulnerability affects the Navigator for i component and related system services. Patches are expected to be available from IBM; users should review IBM's security bulletin for specific remediation guidance.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-12: disclosed