CVE-2026-18099

8.9

IBM · i

A cross-site scripting vulnerability in IBM i allows authenticated remote attackers to inject malicious scripts into web pages viewed by other users.

Executive summary

A high severity cross-site scripting vulnerability in IBM i could allow an authenticated attacker to execute malicious scripts in the context of other users.

Vulnerability

This is a stored or reflected cross-site scripting vulnerability occurring due to improper neutralization of input during web page generation. An attacker requires authenticated access to the system to trigger the vulnerability, which then executes in the victim's browser session.

Business impact

With a CVSS score of 8.9, this vulnerability presents a serious risk of session hijacking, credential theft, or unauthorized actions performed on behalf of legitimate users. The ability to manipulate web content in a business critical platform like IBM i could lead to significant operational disruption and data exposure.

Remediation

Immediate Action: Install the specific Program Temporary Fix (PTF) for your respective IBM i version: 7.6 (SJ10887), 7.5 (SJ10888), 7.4 (SJ10890), or 7.3 (SJ10891).

Proactive Monitoring: Monitor web application traffic for patterns indicative of script injection, such as unusual character sequences in input fields or URL parameters.

Compensating Controls: Implement a Content Security Policy (CSP) to mitigate the impact of cross-site scripting and use a Web Application Firewall (WAF) to filter malicious input.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

System administrators must prioritize the installation of the provided PTFs to close this security gap. Prompt remediation is essential to maintain the integrity of administrative web interfaces and protect user sessions.

More IBM CVEs