What is CVE-2026-18148?
A vulnerability in IBM i versions 7.6, 7.5, 7.4, and 7.3 allows a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output neutralization for logs. This could facilitate further attacks through log manipulation. Users are recommended to apply the relevant security patches provided by IBM.
Azərbaycanca: IBM i 7.6, 7.5, 7.4 və 7.3 versiyalarında qeydiyyatdan keçmiş uzaqdan autentifikasiya olunmuş hücumçuya Navigator log fayllarına özbaşına məzmun yeritməyə imkan verən zəiflikdir. Bu, log neytrallaşdırılmasındakı səhv səbəbindən baş verir və loqların manipulyasiyası ilə sonrakı hücumlara şərait yarada bilər. İstifadəçilərə IBM tərəfindən təqdim edilən müvafiq təhlükəsizlik yamaqlarını tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: IBM
FAQ2
Which versions of IBM i are affected by CVE-2026-18148?
This vulnerability affects IBM i versions 7.6, 7.5, 7.4, and 7.3.
Does an attacker need to be authenticated to exploit CVE-2026-18148?
Yes, the attacker must be a remote authenticated user to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.