Sceawere

Vulnerability Detail

CVE-2026-18150UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Information Disclosure Race Condition

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-12T20:17:41.190Z",
  "pubdate": "2026-08-12T20:17:41.190Z",
  "executiveSummary": "This security advisory details a sensitive information disclosure vulnerability affecting IBM i versions 7.6, 7.5, 7.4, and 7.3. The vulnerability arises due to a race condition flaw within the system architecture, which can be leveraged by a remote authenticated attacker to harvest unauthorized sensitive information. The flaw presents notable risk implications regarding confidentiality, as successful exploitation exposes internal system data that should otherwise be strictly restricted based on standard access controls.\nThe exploitation of this vulnerability requires the attacker to possess authenticated access to the target system. Interaction involves timing-dependent operations to trigger the underlying race condition during concurrent execution threads or resource requests. Although remote authentication is a prerequisite, the inherent nature of race conditions allows for programmatic exploitation once the initial access boundary is crossed. Organizations running the affected IBM i versions face potential unauthorized data exposure, which could facilitate subsequent attack vectors or lead to regulatory and compliance violations due to compromised data confidentiality. Immediate attention to vendor-supplied patches and defensive hardening configurations is strongly recommended to neutralize the risk.",
  "technicalDetails": "The vulnerability stems from a race condition flaw present in IBM i versions 7.6, 7.5, 7.4, and 7.3. Race conditions occur when multiple concurrent execution threads access shared system resources or memory structures without adequate synchronization mechanisms, such as proper mutexes or locking primitives. In this specific scenario, asynchronous operations or interleaved execution paths allow an authenticated process or user to bypass logical security checks or access temporary states where sensitive data resides unprotected for brief windows of time.\nThe attack flow requires the threat actor to have established valid credentials, granting remote authenticated access to the target IBM i environment. The attacker initiates a series of concurrent requests or operations designed to target the vulnerable component during periods of high contention or specific operational sequences. By meticulously timing these parallel requests, the attacker induces a race condition, exploiting the window between the initiation of a security check and the actual access or allocation of the targeted resource.\nWhen the race condition is successfully triggered, the underlying subsystem inadvertently exposes sensitive information that is processed or stored during the transaction. The vulnerable component fails to maintain atomic operations, leading to inconsistent state handling and unauthorized data disclosure to the requesting session. The post-exploitation impact is primarily centered around information disclosure, where the retrieved sensitive data can be leveraged to map internal system configurations, uncover user credentials, or facilitate further compromise within the IBM i ecosystem. Network exposure is tied to the services providing authenticated access to the affected IBM i versions, necessitating that attackers reach the management or application interfaces capable of triggering the asynchronous flaw."
}
CVE-2026-18150: IBM i Information Disclosure Race Condition (MEDIUM Severity, CVSS: 4.3) - Sceawere