CVE-2026-18148: IBM i is Affected By Multiple Vulnerabilities in Navigator for i
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs.
Other sources
IBM i could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM i Navigator for ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ10887 - Upgrade
Upgrade
IBM i Navigator for ito a version that resolves this vulnerability.Fixed in 7.5Patch SJ10888 - Upgrade
Upgrade
IBM i Navigator for ito a version that resolves this vulnerability.Fixed in 7.4Patch SJ10890 - Upgrade
Upgrade
IBM i Navigator for ito a version that resolves this vulnerability.Fixed in 7.3Patch SJ10891
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18148?
The severity of CVE-2026-18148 is rated medium with a score of 4.3.
What systems are affected by CVE-2026-18148?
CVE-2026-18148 affects IBM i versions 7.6, 7.5, 7.4, and 7.3.
What type of attack is possible with CVE-2026-18148?
CVE-2026-18148 allows a remote authenticated attacker to inject arbitrary content into Navigator log files.
How can CVE-2026-18148 vulnerabilities be mitigated?
To mitigate CVE-2026-18148, organizations should apply the latest security updates and patches provided by IBM.
What impact does CVE-2026-18148 have on confidentiality, integrity, and availability?
CVE-2026-18148 has no impact on confidentiality, low impact on integrity, and no impact on availability.