Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized file placement via Navigator
Action: Immediate Patch
AI Analysis

Impact

An authenticated user can upload files with Navigator for i that bypass intended configuration checks, placing files in locations that should be prohibited. The flaw is a path traversal style weakness (CWE-22) that allows file creation in unintended directories. Based on the description, it is inferred that an attacker could place malicious code or data in protected parts of the system, which would affect integrity and could potentially compromise confidentiality.

Affected Systems

IBM i releases 7.3, 7.4, 7.5, and 7.6 are affected when running the Navigator for i and Digital Certificate Manager for i. PTFs that address the flaw include SJ11187/SJ11394 for 7.3, SJ11200/SJ11335 for 7.4, SJ11197/SJ11336 for 7.5, and SJ11196/SJ11337 for 7.6.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The exploitation route is a remote authenticated attack that leverages the Navigator interface; it requires valid credentials but otherwise does not need additional privileges beyond what the user already has. Because the flaw is limited to users who already have upload rights, the risk is lower than a privilege‑escalation or code‑execution flaw; however, it remains actionable for a malicious insider or a compromised user, as inferred from the attack requirements.

Generated by OpenCVE AI on September 15, 2026 at 13:13 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ11196 SJ11337 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11196 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11337 7.5SJ11197 SJ11336 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11197 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11336 7.4SJ11200 SJ11335 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11200 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11335 7.3SJ11187 SJ11394 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11187 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11394 IBM i Release5770-SS1 Option 34 PTF Number(s)PTF Download Link(s)7.6SJ11377 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11377 7.5SJ11376 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11376 7.4SJ11375 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11375 7.3SJ11374 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11374 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTFs listed for each release (e.g., 7.6 SJ11196, SJ11337; 7.5 SJ11197, SJ11336; 7.4 SJ11200, SJ11335; 7.3 SJ11187, SJ11394) to patch Navigator for i and Digital Certificate Manager for i.
  • If an immediate patch is not possible, restrict the ability to upload files in Navigator by tightening configuration or disabling the upload feature for all profiles that are not explicitly required to use it.
  • Audit Navigator configuration to ensure that only intended file locations are writable and that user profiles do not exceed the minimal privileges needed for operation.
  • Consider upgrading to a supported version of IBM i that includes the fixes if the current installation is unsupported.

Generated by OpenCVE AI on September 15, 2026 at 13:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.
Title IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.
First Time appeared Ibm
Ibm i
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T19:22:58.738Z

Reserved: 2026-07-31T17:56:14.883Z

Link: CVE-2026-18515

cve-icon Vulnrichment

Updated: 2026-09-14T19:14:52.373Z

cve-icon NVD

Status : Received

Published: 2026-09-14T19:17:16.407

Modified: 2026-09-14T20:16:43.100

Link: CVE-2026-18515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:15:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')