SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-18515

MEDIUM · CVSS 4.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM i versions 7.6, 7.5, 7.4, and 7.3 are vulnerable to a flaw that permits remote authenticated attackers to bypass Navigator for i's file placement restrictions, potentially allowing unauthorized file uploads to unintended locations within the file system. This vulnerability could lead to unauthorized access or manipulation of sensitive data, making it critical for organizations using these IBM i versions to prioritize remediation. System administrators and security teams should assess their configurations and user permissions to mitigate the risk associated with this vulnerability.

CVE
CVE-2026-18515
Severity
MEDIUM
CVSS
4.3
EPSS
0.28%

Original NVD Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.