Executive brief
IBM i is an enterprise operating system for business-critical applications. Navigator for i is a web-based management interface used to administer IBM i systems. An authenticated user can exploit a privilege management flaw to escalate their access to root-level permissions and execute arbitrary commands, potentially compromising the entire system and any sensitive data it stores.
Technical details
CVE-2026-18683 is a privilege escalation vulnerability (CWE-269: Improper Privilege Management) in IBM i's Navigator for i web interface. An authenticated attacker with low privileges can bypass authorization checks to escalate to root-level access and execute arbitrary system commands. The vulnerability requires authentication and network access to Navigator for i, but no user interaction. A successful exploit grants complete control over the affected IBM i system, including access to all data and ability to modify system configuration. Patches are available from IBM for affected versions (7.3, 7.4, 7.5, and 7.6).
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-12: disclosed