Executive brief
IBM i is a server operating system used to run business-critical applications for enterprises. An authenticated user can inject arbitrary JavaScript code into the Navigator for i web administration interface, which is then executed in other users' trusted browser sessions. This could allow an attacker to steal login credentials or manipulate administrative functions without detection.
Technical details
IBM i 7.3–7.6 contains a stored cross-site scripting (XSS) vulnerability in the Navigator for i web UI due to improper neutralization of user input during web page generation (CWE-79). The vulnerability requires authentication and allows an attacker to embed malicious JavaScript that persists in the application and executes when other users access the affected component. An authenticated attacker can alter intended functionality and potentially harvest credentials within a trusted session. Patch availability is tracked by IBM under CVE-2026-16694.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-12: disclosed