IBM i 7.x local auth privilege escalation via Navigator for i debugger
CVE-2026-18509 Published on August 13, 2026
IBM i is Affected By A Prvilege Escalation Vulnerability []
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could allow the attacker to access or manipulate sensitive data on the system, or create new profiles with elevated privileges on the IBM i system.
Vulnerability Analysis
CVE-2026-18509 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-18509 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-18509
Want to know whenever a new CVE is published for IBM I? stack.watch will email you.
Affected Versions
IBM i:- Version 7.6 is affected.
- Version 7.5 is affected.
- Version 7.4 is affected.
- Version 7.3 is affected.