CVE-2026-18151: IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.
Other sources
IBM i could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.6Patch 7.6SJ11196 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.6Patch 7.6SJ11377 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.5Patch 7.5SJ11376 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.4Patch 7.4SJ11375 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.3Patch 7.3SJ11374 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.4Patch 7.4SJ11200 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.5Patch 7.5SJ11197 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.3Patch 7.3SJ11187
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated to exploit the race condition during the WebSocket handshake process.
What is the potential impact?
Successful exploitation could allow an authenticated remote attacker to obtain sensitive information.