Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to an interpretation conflict in the multipart parser.
Published: 2026-08-12
Score: 3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is caused by an interpretation conflict in the multipart parser of IBM i, representing a CWE‑436 weakness in access control. This flaw allows a remote authenticated attacker to bypass security restrictions. It does not provide arbitrary code execution but undermines the integrity of the system’s access controls, potentially allowing an attacker to execute actions beyond their authorized privileges.

Affected Systems

IBM i versions 7.3 through 7.6 are affected. The specific patch numbers depend on the release: SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, and SJ10891 for 7.3. Unsupported or older versions should be upgraded to a supported and fixed version.

Risk and Exploitability

The CVSS score is 3, indicating a low overall severity. EPSS data is unavailable and the vulnerability is not listed in the KEV catalog. The attack requires remote authenticated access, implying that valid credentials are necessary. Although the risk of exploitation is low, the bypass of security restrictions can still facilitate further compromise in a broader attack scenario.

Generated by OpenCVE AI on August 13, 2026 at 00:37 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ10887 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10887 7.5SJ10888 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10888 7.4SJ10890 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10890 7.3SJ10891 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10891 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Install the PTF that addresses the vulnerability for your IBM i release (SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, or SJ10891 for 7.3).
  • If operating a version of IBM i that is no longer supported, upgrade to the latest supported release that includes the fix.
  • Until the patch or upgrade is applied, restrict network access to the Navigator for i service to trusted IP addresses to reduce the attack surface.

Generated by OpenCVE AI on August 13, 2026 at 00:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Thu, 13 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to an interpretation conflict in the multipart parser.
Title IBM i is Affected By security restrictions bypass in Navigator for i
First Time appeared Ibm
Ibm i
Weaknesses CWE-436
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T16:26:44.959Z

Reserved: 2026-07-29T14:53:53.973Z

Link: CVE-2026-18246

cve-icon Vulnrichment

Updated: 2026-08-13T16:26:41.243Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T17:17:25.527

Modified: 2026-08-17T14:50:52.857

Link: CVE-2026-18246

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:45:02Z

Weaknesses