Junglewise Threat Intelligence

CVE-2026-18509: IBM i privilege escalation in Navigator debugger

CVE-2026-18509 · Severity: high · CVSS 8.2 · Published 2026-08-13

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is an enterprise operating system used to run mission-critical business applications and databases. A vulnerability in the Navigator debugger component allows authenticated local users to escalate their privileges, potentially gaining access to sensitive data, manipulating system resources, or creating new administrative accounts. This could compromise the entire system and all applications running on it.

Technical details

The vulnerability is an improper authorization (CWE-285) in the IBM i Navigator for i debugger and Debug Service components. A local authenticated attacker can exploit this via an unspecified mechanism to gain privilege escalation. The attack requires local access and existing authentication credentials, but does not require user interaction or network access. Successful exploitation allows an attacker to access sensitive data, manipulate system configuration, or create privileged user profiles. IBM has released PTF (Program Temporary Fix) updates for all affected versions (7.3, 7.4, 7.5, and 7.6).

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-13: disclosed
  • 2026-08-13: patched: PTF updates released for all affected versions

References

Related threats