CVE-2026-18515

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 19:17

Updated : 2026-09-14 20:16


NVD link : CVE-2026-18515

Mitre link : CVE-2026-18515

CVE.ORG link : CVE-2026-18515


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')