Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability.
Published: 2026-08-12
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw in IBM i Navigator for i allows an authenticated remote user to request files outside the intended directories, enabling the attacker to read confidential data and overwrite or delete files. The vulnerability is mapped to CWE-22 and is scored with a CVSS of 4.3, indicating moderate severity. The attack does not provide privilege escalation, but it does compromise confidentiality and integrity of system files and any data stored there.

Affected Systems

IBM i operating system versions 7.6, 7.5, 7.4, and 7.3 running Navigator for i are affected. PTFs that remediate the issue are SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, and SJ10891 for 7.3. Users on unsupported versions are advised to upgrade to a supported release that includes the fix.

Risk and Exploitability

The CVSS score of 4.3 signals a moderate risk; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires remote authentication, an attacker must first gain valid credentials or access to an authenticated session; once authenticated, the path traversal can be leveraged. The likelihood of exploitation is therefore limited to environments where credentials are compromised or where the attacker can deploy an authenticated session.

Generated by OpenCVE AI on August 12, 2026 at 23:29 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ10887 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10887 7.5SJ10888 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10888 7.4SJ10890 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10890 7.3SJ10891 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10891 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the PTF listed for your IBM i version (SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, SJ10891 for 7.3) to patch the path traversal flaw.
  • If the system is running an unsupported version of IBM i, upgrade to a supported and patched release as recommended by IBM.
  • Disable or restrict the Navigator for i service to limit the attack surface if the functionality is not required.
  • Ensure file paths received by the application are properly validated and confined to allowed directories to mitigate future path traversal attempts.

Generated by OpenCVE AI on August 12, 2026 at 23:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Wed, 12 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal vulnerability.
Title IBM i is Affected By Path Traversal Vulnerability in Navigator for i
First Time appeared Ibm
Ibm i
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-12T17:53:18.403Z

Reserved: 2026-07-24T14:52:03.602Z

Link: CVE-2026-17094

cve-icon Vulnrichment

Updated: 2026-08-12T17:53:10.939Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T17:17:24.443

Modified: 2026-08-17T14:20:21.200

Link: CVE-2026-17094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:30:10Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')