Sceawere
Vulnerability Detail
CVE-2026-18509UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM i Navigator Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- i
- Attack Type
- CWE-285 Improper Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-08-13T21:17:45.057Z",
"pubdate": "2026-08-13T21:17:45.057Z",
"executiveSummary": "This vulnerability involves a privilege escalation flaw within the Navigator for i component across multiple versions of the IBM i operating system, specifically versions 7.6, 7.5, 7.4, and 7.3. The security defect enables a local authenticated attacker to leverage the system debugger functionality exposed through Navigator for i to elevate their access privileges maliciously. Successfully exploiting this vulnerability carries severe risk implications for system confidentiality, integrity, and availability, as it grants unauthorized actors the ability to access or manipulate highly sensitive system data. Furthermore, the attacker can leverage the escalated privileges to provision new user profiles endowed with elevated administrative rights directly on the underlying IBM i system. Exploitation requires the attacker to possess prior local authentication to the system and interact with the vulnerable debugger component of the interface. This capability effectively undermines the principle of least privilege, allowing standard users to bypass security boundaries and achieve full administrative control over the targeted enterprise environment.",
"technicalDetails": "The vulnerability resides within the Navigator for i debugger component of IBM i operating system versions 7.6, 7.5, 7.4, and 7.3. The root cause stems from insufficient access controls and inadequate privilege validation during debugging operations initiated through the web-based management interface. Specifically, the component fails to properly restrict debugger capabilities to authorized administrators, permitting standard users with local authentication to execute privileged debugging routines.\nThe attack flow begins when a locally authenticated attacker establishes a session with the Navigator for i interface. The attacker then interacts with the vulnerable debugging subsystem. Because the component processes debugging commands without enforcing strict privilege separation, the attacker can manipulate execution contexts or inject unauthorized control instructions. This abuse of the debugging functionality allows the execution of arbitrary operating system commands or administrative APIs within the security context of a privileged service or the root equivalent profile on IBM i.\nPost-exploitation impact is critical. Once the attacker successfully executes code via the debugger mechanism, they gain the ability to read, modify, or delete sensitive data across the system. Additionally, the attacker can programmatically interact with system security APIs to create new user profiles assigned with elevated privileges, ensuring persistent and unauthorized administrative access to the IBM i environment. Network exposure is localized to the interfaces hosting Navigator for i, but the core prerequisite mandates that the threat actor holds valid local authentication credentials prior to initiating the exploitation sequence."
}