Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs.
Published: 2026-08-12
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote authenticated attacker can inject arbitrary content into Navigator log files on IBM i 7.6, 7.5, 7.4, or 7.3 due to improper output neutralization for logs. This weakness is classified as CWE‑117 and can corrupt log data or facilitate the concealment of malicious activity. The vulnerability does not directly provide code execution or privilege escalation, but compromised logs may aid attackers in evading detection or causing confusion in troubleshooting.

Affected Systems

The affected systems are IBM i product releases 7.6, 7.5, 7.4, and 7.3, each of which includes a Navigator component. IBM provides specific patch install fixes for these releases: 7.6SJ10887 for 7.6, 7.5SJ10888 for 7.5, 7.4SJ10890 for 7.4, and 7.3SJ10891 for 7.3. Users of unsupported or older releases should consider upgrading to a supported and fixed version as recommended by IBM.

Risk and Exploitability

The CVSS score is 4.3, indicating a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires the attacker to be authenticated to the Navigator service, which limits the scope compared to an unauthenticated vector. Once authenticated, the attacker can tamper with log contents, potentially leading to data corruption or misleading audit trails, but the likelihood of exploitation remains moderate due to the need for valid credentials and the limited impact surface.

Generated by OpenCVE AI on August 12, 2026 at 22:37 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ10887 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10887 7.5SJ10888 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10888 7.4SJ10890 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10890 7.3SJ10891 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10891 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the PTF for your IBM i release – 7.6SJ10887 for v7.6, 7.5SJ10888 for v7.5, 7.4SJ10890 for v7.4, or 7.3SJ10891 for v7.3. This patch neutralizes the improper output handling in Navigator logs.
  • If a PTF is not available, upgrade to a supported and fixed version of IBM i as advised by IBM.
  • Monitor Navigator log files for unexpected or injected content, and cross‑check configuration and authentication logs periodically for anomalies. Implementing logging integrity checks can help detect tampering before it causes operational issues.

Generated by OpenCVE AI on August 12, 2026 at 22:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs.
Title IBM i is Affected By Multiple Vulnerabilities in Navigator for i
First Time appeared Ibm
Ibm i
Weaknesses CWE-117
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T14:20:30.058Z

Reserved: 2026-07-28T19:12:44.960Z

Link: CVE-2026-18148

cve-icon Vulnrichment

Updated: 2026-08-13T14:20:24.700Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T20:17:41.063

Modified: 2026-08-17T17:49:38.100

Link: CVE-2026-18148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T04:00:08Z

Weaknesses
  • CWE-117

    Improper Output Neutralization for Logs