CVE-2026-18515
published 2026-09-14CVE-2026-18515: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked…
PriorityP425medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.28%
18.1th percentile
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | i | — | — |
| ibm | i | — | — |
| ibm | i | — | — |
| ibm | i | — | — |
| weblate | weblate | >= 0 < 5.17 | 5.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration.
ghsa_unreviewed·2026-09-14
CVE-2026-18515 [MEDIUM] CWE-22 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support did not intend, but only if the profile could already do that by itself.
GHSA
Weblate: Improper access control for pending tasks in API
ghsa·2026-04-16
CVE-2026-33212 [LOW] CWE-284 Weblate: Improper access control for pending tasks in API
Weblate: Improper access control for pending tasks in API
### Impact
The API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope.
### Patches
* https://github.com/WeblateOrg/weblate/pull/18515
### Workarounds
The attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits.
### References
This issue was identified by Michal Čihař.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-14
Published