Authorization Bypass in IBM i DDM Target Dispatcher
A vulnerability in the IBM i DDM target dispatcher allows remote attackers to manipulate database transactions due to improper authorization handling.
CVE search metadata
CVE search record: CVE-2026-18175. Severity: high. CVSS: 8.1. KEV: no. Product: IBM i (7.6, 7.5, 7.4, 7.3). Brief: Authorization Bypass in IBM i DDM Target Dispatcher. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-18175/
IBM i versions 7.6, 7.5, 7.4, and 7.3 contain a vulnerability identified as CVE-2026-18175 that impacts the Distributed Data Management (DDM) target dispatcher. The flaw is rooted in improper authorization checks, which can be exploited by a remote, unauthenticated attacker to manipulate database transactions. This unauthorized access could lead to the modification, corruption, or deletion of sensitive data managed by the DDM service, effectively bypassing expected access control constraints. Defenders should prioritize auditing DDM service configurations and restricting network access to the DDM target dispatcher to mitigate the risk of exploitation.
Impact
The vulnerability poses a significant risk to data integrity within environments utilizing IBM i systems. If exploited, an attacker could manipulate database entries without proper credentials, potentially resulting in unauthorized data modification or corruption. Systems exposed to the public internet or untrusted network segments are at the highest risk of compromise.
Recommendation
- Audit the use of the DDM service across the IBM i environment to determine if remote access is required.
- Restrict access to the DDM target dispatcher port to trusted IP addresses or internal subnets via network firewalls.
- Monitor IBM i logs for unusual transaction activity associated with DDM-connected remote sessions.
- Apply official vendor patches or PTFs provided by IBM as soon as they become available for versions 7.6, 7.5, 7.4, and 7.3.
Immediate actions
Restrict access to DDM target dispatcher ports via firewall
Mitigations
Monitor for IBM security updates for IBM i versions 7.3 through 7.6
CVE-2026-18175