Sceawere

Vulnerability Detail

CVE-2026-18099UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Cross-Site Scripting Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.9
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.9",
  "pubDate": "2026-08-12T20:17:40.827Z",
  "pubdate": "2026-08-12T20:17:40.827Z",
  "executiveSummary": "This vulnerability affects IBM i versions 7.3, 7.4, 7.5, and 7.6, involving an improper neutralization of user-controlled input vulnerability.\nThe flaw allows a remote authenticated attacker to execute arbitrary script code within the context of the user's session.\nThe primary impact of this security deficiency includes potential session hijacking, unauthorized actions performed on behalf of the victim, and the manipulation of rendered web interfaces.\nExploitation requires the attacker to have valid authentication credentials and the ability to interact with the vulnerable application component over the network.\nThe root cause stems from the insufficient sanitization or validation of untrusted input before rendering it back to the client, leading to script injection vulnerabilities.\nRisk implications are significant for environments where users possess elevated privileges, as successful script execution could compromise sensitive data or administrative functions within the IBM i operating system interfaces.",
  "technicalDetails": "The vulnerability resides in the input handling mechanisms of IBM i versions 7.3, 7.4, 7.5, and 7.6, specifically within components that process and render user-supplied data.\nThe root cause is classified as improper neutralization of user-controlled input, which typically manifests as Cross-Site Scripting (XSS) when output is reflected or stored without adequate contextual encoding or escaping.\nAuthentication requirements dictate that an attacker must possess valid credentials to access the vulnerable interface, meaning anonymous or unauthenticated exploitation over the network is not directly achievable.\nPrivilege requirements depend on the specific vulnerable endpoint, but standard authenticated users can generally target their own sessions or potentially escalate interaction if administrative interfaces are targeted.\nNetwork exposure involves standard protocols used to access IBM i web-based management tools or application interfaces, allowing remote authenticated users to transmit malicious payloads.\nThe attack flow begins when an attacker crafts a malicious input string containing arbitrary script code, such as JavaScript, designed to execute within a victim's browser context.\nThe attacker submits this payload via vulnerable input vectors, where the application accepts the data without proper sanitization or validation.\nThe vulnerable component subsequently reflects or stores the input, incorporating it into the generated response sent back to the client's browser.\nUpon receiving the unescaped payload, the victim's browser parses and executes the embedded script code within the security context of the affected application session.\nPayload behavior during post-exploitation can include accessing session tokens, reading sensitive DOM elements, performing unauthorized asynchronous requests on behalf of the user, or defacing the application interface."
}
CVE-2026-18099: IBM i Cross-Site Scripting Vulnerability (HIGH Severity, CVSS: 8.9) - Sceawere