Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-supplied path input.
Published: 2026-08-12
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper validation of user-supplied path input in IBM i Navigator for i, allowing a remote authenticated attacker to access files and directories that should not be exposed. This flaw is a classic example of a path traversal issue, classified as CWE-22. The consequence is the disclosure of potentially confidential data, which could compromise the confidentiality and integrity of the affected system.

Affected Systems

IBM i releases 7.3, 7.4, 7.5, and 7.6 running Option 3 are vulnerable. The impact applies to all supported versions within those releases, and users of unsupported versions should consider upgrading to a fixed product version. Patching with the following Fix Related Files (FRFs) is recommended: SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, and SJ10891 for 7.3.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity for this flaw. EPSS data is not available, making it unclear how frequently attackers target this issue, but the lack of a KEV listing suggests no large-scale exploitation has been observed. The flaw requires authentication, so only users with valid credentials can exploit it; attackers typically need to log in via the Navigator for i interface or a related service to submit the malicious path. Given the availability of official patches, the risk can be mitigated by applying the recommended updates.

Generated by OpenCVE AI on August 12, 2026 at 22:48 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ10887 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10887 7.5SJ10888 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10888 7.4SJ10890 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10890 7.3SJ10891 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10891 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM PTFs: SJ10887 for version 7.6, SJ10888 for 7.5, SJ10890 for 7.4, and SJ10891 for 7.3
  • If running an unsupported IBM i version, upgrade to a supported release that contains the fix
  • Enforce strict input validation in any custom code that passes paths to the Navigator for i component

Generated by OpenCVE AI on August 12, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-supplied path input.
Title IBM i is Affected By Multiple Vulnerabilities in Navigator for i
First Time appeared Ibm
Ibm i
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-12T19:19:12.831Z

Reserved: 2026-07-28T17:50:59.026Z

Link: CVE-2026-18106

cve-icon Vulnrichment

Updated: 2026-08-12T17:29:42.734Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T17:17:25.120

Modified: 2026-08-17T14:15:27.730

Link: CVE-2026-18106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:00:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')