Executive brief
IBM i is an enterprise operating system used to run mission-critical business applications. CVE-2026-18144 is an authorization bypass vulnerability that allows authenticated remote attackers to circumvent security restrictions, potentially leading to unauthorized access to sensitive system resources and data.
Technical details
CVE-2026-18144 is an improper authorization vulnerability in IBM i Navigator that allows authenticated remote attackers to bypass security restrictions through unknown authorization flaws. The vulnerability requires valid authentication credentials and network access to the affected system. An attacker with legitimate user credentials can exploit this to gain unauthorized access to protected resources or perform actions beyond their assigned privilege level. Remediation involves applying IBM security patches as described in IBM Security Bulletin addressing multiple Navigator vulnerabilities across IBM i versions 7.3 through 7.6.
Affected products
- IBM i 7.6, 7.5, 7.4, 7.3
Timeline
- 2026-08-12: disclosed