CVE-2026-18835 affects IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1. The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the affected system. The root cause is improper neutralization of special elements used in OS commands, classified as a command injection vulnerability. Successful exploitation could lead to full system compromise by an authenticated remote attacker. IBM has published a support advisory with remediation guidance. The vulnerability carries a high severity rating given its remote exploitability and potential for arbitrary command execution.