{"id":"CVE-2026-18858","title":"IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.","summary":"IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-267"],"vendor":"ibm","product":"i","affected":["i = 7.5","i = 7.6"],"published":"2026-09-04","updated":"2026-09-08","sourceUpdated":"2026-09-08T21:37:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18858","references":[{"url":"https://www.ibm.com/support/pages/node/7285938","label":"psirt@us.ibm.com"}],"tags":["nvd","cve.org"],"epss":0.00096,"epssPercentile":0.00804,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T17:16:09.101996Z"},"ingestedAt":"2026-09-08T15:33:26.961Z","slug":"CVE-2026-18858","body":"## Overview\n\nIBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.\n\n## Affected\n\n- `i = 7.5`\n- `i = 7.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":18.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}