cvefeed.io
Critical SQL Injection Vulnerability in IBM Operational Decision Manager
Article Content
A critical SQL injection vulnerability, CVE-2026-18658, has been identified in IBM Operational Decision Manager versions 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1. This flaw allows unauthenticated attackers to execute arbitrary SQL statements and write a web shell to the application web root, leading to remote code execution. The CVSS base score for this vulnerability is 9.8, indicating a high severity level. Currently, there is no evidence of public proof-of-concept exploits or active exploitation in the wild. Security patches are recommended, and organizations should implement network segmentation and monitor for suspicious activity. The vulnerability was published on September 4, 2026, and is categorized under CWE-89 for improper neutralization of SQL commands.
Key Points: • CVE-2026-18658 affects multiple IBM Operational Decision Manager versions. • The vulnerability allows remote code execution via SQL injection. • No public proof-of-concept or active exploitation reported yet.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.