Remote Code Injection in IBM i Products Affecting Multiple Versions
CVE-2026-18148
4.3MEDIUM
What is CVE-2026-18148?
IBM i versions 7.6, 7.5, 7.4, and 7.3 are susceptible to a vulnerability that allows remote authenticated attackers to exploit improper handling of output in Navigator log files. This vulnerability enables attackers to inject arbitrary content, potentially compromising the integrity and confidentiality of the system’s log data. Organizations using these versions should implement the available patches to mitigate this risk.
Affected Version(s)
i 7.6
i 7.5
i 7.4