Executive brief
IBM i is a midrange server operating system used by enterprises for business-critical applications. Navigator for i is its web-based administration interface. A remote attacker can spoof the Navigator login page to trick users into providing their credentials, gaining unauthorized access to the system and all data it manages.
Technical details
CVE-2026-18847 is an origin validation error (CWE-346) in IBM i's Navigator for i web interface that allows spoofing of the legitimate login page. The vulnerability is triggered via a network-based attack vector and requires user interaction (the victim must enter credentials on the fake login page); no prior authentication is needed. An unauthenticated remote attacker can harvest IBM i system credentials, potentially leading to unauthorized system access, data exfiltration, and control over business-critical infrastructure. Patch availability information is not specified in the advisory.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-12: disclosed