Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system.
Published: 2026-08-13
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local authenticated attacker can leverage a flaw in the Navigator for i debugger to elevate privileges on IBM i 7.3, 7.4, 7.5, and 7.6 systems. The vulnerability allows the attacker to access or manipulate sensitive data and to create profiles with elevated privileges, compromising confidentiality, integrity, and overall system security. The weakness is an access control flaw (CWE‑285).

Affected Systems

IBM i Release 7.3, 7.4, 7.5, and 7.6 are affected. The flaw exists in the Navigator for i debugger component of these releases.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity of this privilege escalation. The EPSS score is not available, so the current exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local authenticated user with inappropriate access to the debugger. If the flaw is exploited, the attacker can gain elevated privileges and potentially compromise all data and processes on the IBM i system.

Generated by OpenCVE AI on August 13, 2026 at 22:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Navigator IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ10887 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11126 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11125 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11124 7.3SJ11128 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11128 https://www.ibm.com/mysupport/s/fix-information IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Install the IBM i Professional Fix Technology updates: apply PTF SJ10887 for Release 7.6, PTF SJ11128 for Release 7.3, and equivalent PTFs for Releases 7.4 and 7.5.
  • If running an unsupported IBM i release, upgrade to a supported, patched version of the product.
  • Restrict or disable access to the Navigator for i debugger, ensuring only authorized users have local authenticated access.

Generated by OpenCVE AI on August 13, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system.
Title IBM i is Affected By A Prvilege Escalation Vulnerability []
First Time appeared Ibm
Ibm i
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:43:18.605Z

Reserved: 2026-07-31T17:16:23.194Z

Link: CVE-2026-18509

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:45.057

Modified: 2026-08-13T21:17:45.057

Link: CVE-2026-18509

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:45:03Z

Weaknesses