Executive brief
IBM i Navigator is a web-based administrative interface for managing IBM i systems. A flaw in path validation allows authenticated attackers to upload files to unintended locations on the file system, potentially placing malicious code or configuration files outside areas that should be restricted by Navigator's access controls. The attacker must already have a valid user account and the underlying system profile must have write permissions to the target location.
Technical details
CVE-2026-18515 is a path traversal vulnerability (CWE-22) in IBM i Navigator for i caused by improper validation of file upload paths. An authenticated attacker can craft malicious file upload requests that bypass Navigator's intended directory restrictions through path manipulation, allowing files to be written to arbitrary locations on the file system. The vulnerability requires valid authentication credentials and is network-accessible. An attacker can achieve arbitrary file placement, but only if the compromised user profile already has write permissions to the target directory. Patches are available via PTF updates for IBM i 7.3, 7.4, 7.5, and 7.6.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-14: disclosed: Security bulletin published
- 2026-09-14: patched: PTF updates available for all affected versions (SJ11196, SJ11197, SJ11200, SJ11187 for Option 3; SJ11377, SJ11376, SJ11375, SJ11374 for Option 34)