---
id: CVE-2026-18515
title: >-
  IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to
  place files into the file system with Navigator for i when they should be
  blocked by Navigator configuration
summary: >-
  IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to
  place files into the file system with Navigator for i when they should be
  blocked by Navigator configuration. This could allow attackers to upload files
  onto the…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-22
vendor: IBM
product: i
affected:
  - i 7.6
  - i 7.5
  - i 7.4
  - i 7.3
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:22:22.797'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18515'
references:
  - url: 'https://www.ibm.com/support/pages/node/7286974'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
epss: 0.00277
epssPercentile: 0.18004
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T19:10:24.138205Z'
ingestedAt: '2026-09-14T19:13:23.472Z'
---

## Overview

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
