Junglewise Threat Intelligence

CVE-2026-18847: IBM i credential harvesting via Navigator spoofing

CVE-2026-18847 · Severity: high · CVSS 8.8 · Published 2026-08-12

Technologies: IBM I. Vendors: IBM.

Executive brief

IBM i is a midrange server operating system used by enterprises for business-critical applications. Navigator for i is its web-based administration interface. A remote attacker can spoof the Navigator login page to trick users into providing their credentials, gaining unauthorized access to the system and all data it manages.

Technical details

CVE-2026-18847 is an origin validation error (CWE-346) in IBM i's Navigator for i web interface that allows spoofing of the legitimate login page. The vulnerability is triggered via a network-based attack vector and requires user interaction (the victim must enter credentials on the fake login page); no prior authentication is needed. An unauthenticated remote attacker can harvest IBM i system credentials, potentially leading to unauthorized system access, data exfiltration, and control over business-critical infrastructure. Patch availability information is not specified in the advisory.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6

Timeline

  • 2026-08-12: disclosed

References

Related threats