Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-18658: IBM Operational Decision Manager allows remote code execution

CVE-2026-18658 · published today
Summary

Several versions of IBM Operational Decision Manager can be tricked into running harmful database commands without any login. An attacker could place their own program on your server and take control of the system. Apply the latest IBM security updates as soon as possible to close this gap.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm operational decision manager 9.6.0.0
Original advisory text
IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.
References
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Type
CWE-89SQL Injection
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-18658 · MITRE
Monitor software like this
Free during beta