{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-18515","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2026-07-31T17:56:14.883Z","datePublished":"2026-09-14T18:26:59.756Z","dateUpdated":"2026-09-14T19:22:58.738Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-09-14T18:26:59.756Z"},"title":"IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","type":"CWE"}]}],"affected":[{"vendor":"IBM","product":"i","versions":[{"status":"affected","version":"7.6"},{"status":"affected","version":"7.5"},{"status":"affected","version":"7.4"},{"status":"affected","version":"7.3"}],"cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286974","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":4.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}}],"solutions":[{"lang":"en","value":"IBM strongly recommends addressing the vulnerability now.\n\n\n\n\n\nIBM i Release5770-SS1 Option 3\nPTF Number(s)PTF Download Link(s)7.6SJ11196\nSJ11337 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11196 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11337 \n\n7.5SJ11197\nSJ11336 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11197 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11336 \n\n7.4SJ11200\nSJ11335 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11200 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11335 \n\n7.3SJ11187\nSJ11394 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11187 \n\n https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11394 \n\n\n\nIBM i Release5770-SS1 Option 34\nPTF Number(s)PTF Download Link(s)7.6SJ11377 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11377 7.5SJ11376 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11376 7.4SJ11375 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11375 7.3SJ11374 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11374 \n\n\n\n\n\n\n\nIBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p><strong>IBM strongly recommends addressing the vulnerability now.</strong></p><p></p><div><table><colgroup><col/><col/><col/></colgroup><thead><tr><td><strong>IBM i Release</strong></td><td><strong>5770-SS1 Option 3<br/></strong><strong>PTF Number(s)</strong></td><td><strong>PTF Download Link(s)</strong></td></tr></thead><tbody><tr><td>7.6</td><td>SJ11196<br/>SJ11337</td><td><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11196\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11196</a></div><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11337\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11337</a></div></td></tr><tr><td>7.5</td><td>SJ11197<br/>SJ11336</td><td><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11197\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11197</a></div><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11336\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11336</a></div></td></tr><tr><td>7.4</td><td>SJ11200<br/>SJ11335</td><td><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11200\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11200</a></div><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11335\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11335</a></div></td></tr><tr><td>7.3</td><td>SJ11187<br/>SJ11394</td><td><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11187\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11187</a></div><div><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11394\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11394</a></div></td></tr></tbody></table></div><div><table><colgroup><col/><col/><col/></colgroup><thead><tr><td><strong>IBM i Release</strong></td><td><strong>5770-SS1 Option 34<br/></strong><strong>PTF Number(s)</strong></td><td><strong>PTF Download Link(s)</strong></td></tr></thead><tbody><tr><td>7.6</td><td>SJ11377</td><td><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11377\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11377</a></td></tr><tr><td>7.5</td><td>SJ11376</td><td><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11376\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11376</a></td></tr><tr><td>7.4</td><td>SJ11375</td><td><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11375\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11375</a></td></tr><tr><td>7.3</td><td>SJ11374</td><td><a href=\"https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11374\" rel=\"nofollow\">https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11374</a></td></tr></tbody></table></div><p></p><p>IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.</p>"}]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-18515","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-09-14T19:10:24.138205Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-14T19:22:58.738Z"}}]}}