Critical SQL Injection Vulnerability in IBM Operational Decision Manager

Critical SQL Injection Vulnerability in IBM Operational Decision Manager

First seen 5 Sep 2026, 01:14 UTC Feedlycvefeed.iodb.gcve.euvuldb.comwww.ionix.io 70.5

Article Content

Browse articles
ThreatCluster

A critical SQL injection vulnerability, CVE-2026-18658, has been identified in IBM Operational Decision Manager versions 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1. This flaw allows unauthenticated attackers to execute arbitrary SQL statements and write a web shell to the application web root, leading to remote code execution. The CVSS base score for this vulnerability is 9.8, indicating a high severity level. Currently, there is no evidence of public proof-of-concept exploits or active exploitation in the wild. Security patches are recommended, and organizations should implement network segmentation and monitor for suspicious activity. The vulnerability was published on September 4, 2026, and is categorized under CWE-89 for improper neutralization of SQL commands.

Key Points: • CVE-2026-18658 affects multiple IBM Operational Decision Manager versions. • The vulnerability allows remote code execution via SQL injection. • No public proof-of-concept or active exploitation reported yet.

Ask AI about this cluster

Timeline

2026-09-04
CVE-2026-18658 published
IBM disclosed a critical SQL injection vulnerability affecting various versions of Operational Decision Manager.
cvefeed.io
2026-09-05
Security advisory issued
Organizations are urged to apply patches and implement security measures to mitigate the vulnerability.
Feedly