Sceawere

Vulnerability Detail

CVE-2026-18847UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Navigator Credential Spoofing

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-346 Origin Validation Error
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-12T17:17:25.920Z",
  "pubdate": "2026-08-12T17:17:25.920Z",
  "executiveSummary": "This vulnerability involves a credential harvesting weakness caused by the spoofing of Navigator for i within IBM i.\nA remote and unauthenticated attacker can exploit this flaw to harvest sensitive user credentials.\nThe affected products include IBM i versions 7.6, 7.5, 7.4, and 7.3.\nThe risk implications are significant, as successful exploitation compromises user authentication tokens and credentials, potentially leading to unauthorized system access and lateral movement.\nAttacker capabilities include remote execution over the network without requiring any prior authentication or privileged access within the targeted environment.\nExploitation requirements rely on the ability to spoof the Navigator for i interface to deceive users into submitting their credentials to a malicious entity.",
  "technicalDetails": "The root cause of the vulnerability stems from insufficient validation or identity verification mechanisms within Navigator for i, allowing malicious actors to spoof the administrative interface.\nThe vulnerable component is Navigator for i, which serves as the web-based management console across the affected IBM i operating system versions.\nAffected versions explicitly encompass IBM i 7.6, 7.5, 7.4, and 7.3.\nAuthentication and privilege requirements are absent for the attacker, as the vulnerability can be leveraged by a remote unauthenticated entity over the network.\nThe attack flow begins when an attacker crafts a spoofed representation of the Navigator for i interface or intercepts legitimate interactions.\nDue to the spoofing capability, unsuspecting users are lured into authenticating through the fraudulent interface.\nDuring this interaction, the user supplies their credentials, believing they are interacting with the legitimate IBM i management console.\nThe spoofed interface captures the submitted authentication material, enabling the attacker to harvest valid user credentials.\nPayload behavior centers on credential interception and logging for subsequent unauthorized access.\nThe post-exploitation impact includes unauthorized session hijacking, administrative privilege escalation if privileged accounts are harvested, and broader compromise of the underlying IBM i system integrity and confidentiality."
}
CVE-2026-18847: IBM i Navigator Credential Spoofing (HIGH Severity, CVSS: 8.8) - Sceawere