Junglewise Threat Intelligence

CVE-2026-18151: IBM i Navigator race condition in WebSocket handshake

CVE-2026-18151 · Severity: medium · CVSS 4.2 · Published 2026-09-14

Executive brief

IBM Navigator for i is a web-based administration tool used to manage IBM i systems. A race condition flaw during WebSocket handshake allows authenticated attackers to obtain sensitive system information. This could expose database credentials, configuration details, or other confidential data needed to manage critical business systems.

Technical details

The vulnerability is a race condition (CWE-362) in the WebSocket handshake process within IBM Navigator for i. A remote authenticated attacker can exploit timing issues during the handshake to access sensitive information. The attack requires valid credentials and network access to the Navigator service, but does not require user interaction. While the CVSS score is modest (4.2), successful exploitation in a race condition context may depend on timing precision and system load conditions. IBM has released PTF patches for affected versions 7.3, 7.4, 7.5, and 7.6.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-09-14: disclosed
  • patched: PTF patches available for all affected versions (7.3, 7.4, 7.5, 7.6)

References

Related threats