Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-18658: IBM Operational Decision Manager allows remote code execution
CVE-2026-18658 · published today
Summary
Several versions of IBM Operational Decision Manager can be tricked into running harmful database commands without any login. An attacker could place their own program on your server and take control of the system. Apply the latest IBM security updates as soon as possible to close this gap.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | operational decision manager | 9.6.0.0 |
Original advisory text
IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.
References
- https://www.ibm.com/support/pages/node/7286196 vendor-advisory patch
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Type
CWE-89SQL Injection
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Monitor software like this
Free during beta