Junglewise Threat Intelligence

CVE-2026-18246: IBM i multipart parser interpretation conflict security bypass

CVE-2026-18246 · Severity: low · CVSS 3 · Published 2026-08-12

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is a server operating system used to run mission-critical business applications. This vulnerability allows an authenticated remote attacker to bypass security restrictions through a flaw in how the multipart message parser interprets data, potentially allowing an attacker to circumvent intended access controls.

Technical details

The vulnerability is an interpretation conflict (CWE-436) in the multipart parser of IBM i. An authenticated remote attacker with high privileges can exploit the flaw by sending specially crafted multipart messages that are interpreted differently than intended, leading to a bypass of security restrictions. The attack requires network access, authentication, high privilege level, and challenging exploit conditions (AC:H). The impact is limited to integrity on a changed security scope, with no confidentiality or availability impact.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-12: disclosed

References

Related threats