Junglewise Threat Intelligence

CVE-2026-18175: IBM i improper authorization in DDM target dispatcher

CVE-2026-18175 · Severity: high · CVSS 8.1 · Published 2026-09-04

Executive brief

IBM i is a business-critical operating system used to run enterprise database and transactional workloads. A remote attacker can bypass authorization controls in the Distributed Data Management (DDM) subsystem to manipulate database transactions without proper credentials, potentially leading to unauthorized data modification or deletion across critical business systems.

Technical details

This vulnerability is an improper authorization flaw (CWE-285) in the DDM target dispatcher component of IBM i. An unauthenticated remote attacker on the network can exploit this by sending specially crafted DDM/DRDA protocol requests to manipulate database transactions, bypassing the authorization checks that normally protect database integrity. No user interaction or authentication is required; exploitation is network-accessible with high complexity. A successful exploit allows an attacker to modify or delete data within protected database transactions. IBM has released PTF (Program Temporary Fix) updates for versions 7.3, 7.4, 7.5, and 7.6.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-09-04: disclosed
  • 2026-09-04: patched: PTFs available: 7.6 (SJ11231, SJ11230), 7.5 (SJ11232, SJ11233), 7.4 (SJ11262, SJ11261), 7.3 (SJ11234, SJ11235)

References

Related threats