Junglewise Threat Intelligence

CVE-2026-18715: IBM i XML external entity injection information disclosure

CVE-2026-18715 · Severity: medium · CVSS 6.5 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise operating system used to run business-critical applications and databases. This vulnerability allows an authenticated remote attacker to read sensitive information from the system by exploiting improper handling of XML external entities (XXE). An attacker with valid credentials could access confidential data, configuration files, or other protected system information.

Technical details

This vulnerability is an XML External Entity (XXE) injection flaw (CWE-611) in IBM i's XML processing. An authenticated attacker can submit maliciously crafted XML that contains external entity references to access sensitive files or system information. The vulnerability requires network access and valid authentication credentials; no user interaction is needed. An attacker can achieve information disclosure of confidential data. IBM has released PTF patches (SJ10874, SJ10875, SJ10876, SJ10877 for releases 7.6, 7.5, 7.4, and 7.3 respectively) to address this issue.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed
  • 2026-08-13: patched: PTF patches available for affected versions

References

Related threats