Description
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
Published: 2026-08-12
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Authenticated users of IBM i may exploit a flaw in Navigator for i that allows privilege escalation to a root user, enabling the execution of arbitrary commands. The weakness involves an OS Command Injection vulnerability (CWE‑78). No data indicates that exploitation can occur without valid credentials, so attackers must first authenticate to the system. If successful, the attacker gains full administrative control, compromising all system confidentiality, integrity, and availability.

Affected Systems

IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected. IBM issued PTFs SJ10887, SJ10888, SJ10890, and SJ10891 for the 7.6, 7.5, 7.4, and 7.3 releases respectively, under the Release 5770‑SS1 Option 3 configuration. The vulnerability is relevant for any system running an unsupported IBM i version; these versions should be replaced with a supported and patched release.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score is not available, so the current estimate of exploitation probability is unknown, but the lack of KEV listing suggests no widespread exploitation has been observed yet. Exploitation requires authentication to Navigator for i, after which elevated privileges can be obtained. The combination of high impact and the need for user credentials makes the risk significant for environments with broad user access or weak account controls.

Generated by OpenCVE AI on August 13, 2026 at 00:18 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 3 PTF Number(s)PTF Download Link(s)7.6SJ10887 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10887 7.5SJ10888 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10888 7.4SJ10890 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10890 7.3SJ10891 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10891 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the appropriate PTF (SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, or SJ10891 for 7.3) to address the OS Command Injection flaw.
  • Deploy the PTFs for Release 5770‑SS1 Option 3 across all IBM i systems promptly and maintain a patch management schedule to ensure future vulnerabilities are addressed.
  • If operating an unsupported IBM i release, upgrade to a supported and patched version before the vulnerability is fixed.

Generated by OpenCVE AI on August 13, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Wed, 12 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
Title IBM i is Affected By privilege escalation in Navigator for i
First Time appeared Ibm
Ibm i
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-12T17:20:12.467Z

Reserved: 2026-08-03T15:43:22.766Z

Link: CVE-2026-18683

cve-icon Vulnrichment

Updated: 2026-08-12T17:18:29.462Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T17:17:25.790

Modified: 2026-08-17T14:38:47.540

Link: CVE-2026-18683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:30:06Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')