Sceawere

Vulnerability Detail

CVE-2026-18846UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Host Server Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
IBM
Product
i
Attack Type
CWE-787 Out-of-bounds Write
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the host servers, a remote attacker could leverage this vulnerability to cause a denial-of-server (DoS) for that server.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-13T20:17:19.713Z",
  "pubdate": "2026-08-13T20:17:19.713Z",
  "executiveSummary": "This vulnerability involves a buffer overflow flaw within IBM i operating system host servers, stemming from the improper validation of client-supplied data. Specifically, versions 7.6, 7.5, 7.4, and 7.3 are impacted.\nA remote attacker can leverage this security defect by transmitting specially crafted, malformed requests directly to one of the targeted host servers.\nSuccessful exploitation of this vulnerability results in a denial-of-service (DoS) condition, rendering the specific host server unavailable and disrupting critical system services.\nThe risk implications are operational disruption, as the affected host service crashes or becomes unresponsive upon processing the malicious payload.\nThe attacker capabilities are limited to causing a denial-of-service, with no explicit mention of remote code execution or privilege escalation vectors in the baseline disclosure.\nExploitation requirements include network connectivity to the vulnerable IBM i host servers and the capability to craft and transmit malformed network requests designed to trigger the input validation failure.",
  "technicalDetails": "The root cause of the vulnerability is inadequate input validation within the host server components of the IBM i operating system when handling incoming client requests.\nWhen the affected host server receives data exceeding expected boundaries or formatted in an unexpected structure, the lack of proper bounds checking leads to a buffer overflow condition.\nThe affected components are the host servers running on IBM i versions 7.6, 7.5, 7.4, and 7.3.\nNetwork exposure is present because the host servers listen for remote client connections over the network, allowing remote threat actors to reach the vulnerable parsing routines.\nThe attack flow proceeds as follows: First, the remote attacker identifies an exposed IBM i host server. Second, the attacker crafts a malicious request containing oversized or malformed data designed to violate the memory constraints of the input buffer. Third, the attacker transmits this payload over the network to the target host server. Fourth, the server processes the incoming data without adequately validating its length or structure, causing the payload to overflow the allocated memory buffer. Finally, this memory corruption destabilizes the host server process, resulting in an abnormal termination or crash, thereby executing the denial-of-service attack.\nAuthentication and privilege requirements are generally minimal or absent depending on the specific host server configuration, as the attack targets the initial data parsing layers exposed to incoming client connections.\nThe payload behavior focuses entirely on memory corruption to induce a service crash rather than executing arbitrary code or establishing persistence.\nThe post-exploitation impact is strictly confined to a denial-of-service for the targeted host server instance, requiring administrative intervention to restart the service."
}
CVE-2026-18846: IBM i Host Server Buffer Overflow (HIGH Severity, CVSS: 7.5) - Sceawere