Sceawere

Vulnerability Detail

CVE-2026-18235UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i CL Command Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.3
Creation Date
1h ago
Vendor
IBM
Product
i
Attack Type
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input validation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.3",
  "pubDate": "2026-08-12T18:17:28.000Z",
  "pubdate": "2026-08-12T18:17:28.000Z",
  "executiveSummary": "This vulnerability involves an insufficient input validation flaw within IBM i versions 7.6, 7.5, 7.4, and 7.3, which allows a remote authenticated attacker to execute arbitrary Control Language (CL) commands.\nThe primary impact of this security deficiency is unauthorized remote command execution, potentially compromising the integrity, confidentiality, and availability of the underlying operating system.\nThe affected products are IBM i 7.6, 7.5, 7.4, and 7.3.\nThe risk implications are severe, as successful exploitation grants the attacker the ability to interact directly with the operating system command interpreter, bypassing intended security boundaries.\nThe attacker capabilities require prior authentication to the system, indicating that the threat actor must possess valid credentials to initiate the attack sequence.\nExploitation requirements include network access to vulnerable system interfaces and an authenticated session capable of interacting with the vulnerable input handling mechanism.",
  "technicalDetails": "The root cause of the vulnerability stems from insufficient input validation within the affected IBM i components, failing to properly sanitize user-supplied data before passing it to the command processing subsystem.\nThe vulnerable component handles parsing and execution routines for user-supplied inputs, which incorrectly process special characters or command separators.\nAffected versions explicitly include IBM i 7.6, 7.5, 7.4, and 7.3.\nAuthentication requirements mandate that the attacker must be a remote authenticated user, meaning anonymous or unauthenticated exploitation is not feasible.\nPrivilege requirements depend on the specific context of the vulnerable interface, but successful execution typically inherits the execution context or requires specific operational authorizations.\nNetwork exposure is present wherever the vulnerable interfaces are accessible across the network, allowing remote sessions to interact with the input validation mechanism.\nThe attack flow proceeds as follows: First, the remote authenticated attacker connects to the exposed vulnerable service or interface on the IBM i system. Second, the attacker crafts a malicious payload containing arbitrary Control Language (CL) commands embedded within input fields that lack adequate sanitization. Third, the application accepts the malicious input without performing rigorous validation or escaping syntactic control characters. Fourth, the internal parsing routines pass the unsanitized payload directly to the underlying command processor. Finally, the operating system executes the injected arbitrary CL commands with the privileges associated with the execution thread.\nPayload behavior involves the direct interpretation and execution of arbitrary administrative or system-level CL instructions supplied by the attacker.\nPost-exploitation impact includes unauthorized system configuration modifications, data exfiltration, privilege escalation, and potential total system compromise depending on the execution context."
}
CVE-2026-18235: IBM i CL Command Injection (HIGH Severity, CVSS: 8.3) - Sceawere