CVE-2026-18235
NixOS Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-18235 is an OS command injection vulnerability in IBM i that allows a remote authenticated attacker to execute arbitrary Control Language (CL) commands due to insufficient input validation. It affects IBM i versions 7.3, 7.4, 7.5, and 7.6. The vulnerability was published on August 12, 2026, and carries a CVSS v3.1 base score of 8.3 (High) (GitHub Advisory, IBM Support).

Detalhes técnicos

The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), where user-supplied input is not adequately sanitized before being incorporated into Control Language command execution on IBM i. An attacker with low-level authenticated network access can inject malicious CL command sequences that are interpreted and executed by the system. No user interaction is required, and attack complexity is low, making this straightforward to exploit once authentication is obtained (GitHub Advisory, IBM Support).

Impacto

Successful exploitation allows a remote, low-privileged authenticated attacker to execute arbitrary Control Language commands on the affected IBM i system, resulting in high confidentiality and integrity impact and low availability impact. An attacker could read sensitive system data, modify configurations, create or delete objects, and potentially escalate privileges within the IBM i environment. The scope is unchanged, meaning impact is confined to the vulnerable system, but the ability to run arbitrary CL commands represents a significant risk to business-critical IBM i workloads (GitHub Advisory).

Exploração

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.30% (24th percentile), indicating a currently low probability of exploitation within the next 30 days. NVD SSVC assessment notes the vulnerability is not automatable and exploitation has not been observed (GitHub Advisory).

Mitigação e soluções alternativas

IBM has published a support page (node 7283292) addressing this vulnerability; administrators should consult it for available PTFs (Program Temporary Fixes) applicable to IBM i 7.3, 7.4, 7.5, and 7.6 (IBM Support). As interim mitigations, restrict network access to IBM i systems to trusted and authorized users only, enforce strong authentication controls, and audit user privilege levels to minimize the attack surface. Monitor IBM i job logs and audit journals for unexpected or anomalous Control Language command execution.

Reações da comunidade

A brief mention of the vulnerability appeared on Bluesky via the CyberHub blog shortly after disclosure, indicating some community awareness (GitHub Advisory). No significant vendor statements beyond the IBM support page or notable researcher commentary have been identified at this time.

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado NixOS Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NãoSimAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NãoSimAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NãoSimAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NãoSimAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NãoSimAug 18, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades