---
id: CVE-2026-18658
title: >-
  IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1,
  8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection
summary: >-
  IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1,
  8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An
  unauthenticated attacker can execute arbitrary SQL statements and leverage
  database functionality to…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: IBM
product: Operational Decision Manager
affected:
  - operational_decision_manager 9.6.0.0
  - operational_decision_manager 9.5.0.0
  - operational_decision_manager 8.11.1.0
  - operational_decision_manager 8.11.0.1
  - operational_decision_manager 8.12.0.1
  - operational_decision_manager 9.5.0.1
  - operational_decision_manager 9.0.0.1
published: '2026-09-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T21:17:23.990'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18658'
references:
  - url: 'https://www.ibm.com/support/pages/node/7286196'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-10T20:38:13.682174Z'
epss: 0.00432
epssPercentile: 0.36991
ingestedAt: '2026-09-08T15:33:26.961Z'
---

## Overview

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
