CVE-2026-18515: IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.
Other sources
IBM i could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.6Patch 7.6SJ11196 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.6Patch 7.6SJ11377 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.5Patch 7.5SJ11376 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.4Patch 7.4SJ11375 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.3Patch 7.3SJ11374 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch SJ11335 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch SJ11336 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch SJ11337 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch SJ11394
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated and use a profile that already has permission to place files in the target location. The issue does not grant the profile file-system access it did not already have.
What is the practical impact of the Navigator configuration bypass?
Navigator for i may allow file uploads to locations that its configuration was intended to block. This undermines Navigator-level upload restrictions for authenticated users whose existing IBM i profile permissions already allow writes to those locations.
Which IBM i releases are identified as affected?
The affected releases listed are IBM i 7.3, 7.4, 7.5, and 7.6.