Executive brief
IBM i is an enterprise operating system that manages critical business applications and data. A vulnerability in its Navigator administration interface allows authenticated users to read sensitive files and modify system files on the server, potentially compromising the confidentiality and integrity of business operations and sensitive data.
Technical details
CVE-2026-17094 is a path traversal vulnerability (CWE-22) in IBM i's Navigator for i component that stems from improper limitation of pathname access to restricted directories. The vulnerability requires authentication and network access; an authenticated attacker can exploit this to traverse the file system and access or manipulate files outside the intended directory restrictions. The attack surface is the Navigator interface itself, which processes file paths without proper validation. An authenticated remote attacker can obtain sensitive information and manipulate files on the system. IBM has published security bulletins documenting this and related vulnerabilities in Navigator for i.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-12: disclosed