---
id: CVE-2026-18887
title: >-
  IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain
  sensitive information in PASE
summary: >-
  IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain
  sensitive information in PASE. An attacker could exploit this vulnerability to
  access information about process they shouldn't be permitted to access.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: ibm
product: i
affected:
  - i = 7.3
  - i = 7.4
  - i = 7.5
  - i = 7.6
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T21:36:35.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18887'
references:
  - url: 'https://www.ibm.com/support/pages/node/7285940'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00281
epssPercentile: 0.18369
ingestedAt: '2026-09-08T15:33:26.961Z'
---

## Overview

IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.

## Affected

- `i = 7.3`
- `i = 7.4`
- `i = 7.5`
- `i = 7.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
