Impact
IBM i 7.6, 7.5, 7.4 and 7.3 are vulnerable to a privilege escalation flaw in Navigator for i. An authenticated user can leverage the vulnerability to become a root user and run arbitrary commands, providing full control over the affected system.
Affected Systems
IBM i releases 7.3, 7.4, 7.5 and 7.6. The specific affected releases are 7.3, 7.4, 7.5 and 7.6 with any minor or patch updates prior to the supplied PTF numbers.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. Because the exploit requires authentication, an attacker needs valid user credentials or insider access to the Navigator for i service. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of public exploitation does not reduce the risk if privileged users are present. Prompt remediation is therefore necessary.
OpenCVE Enrichment