CVE-2026-18683
published 2026-08-12CVE-2026-18683: IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.66%
49.6th percentile
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | i | — | — |
| ibm | i | — | — |
| ibm | i | — | — |
| ibm | i | — | — |
| weblate | weblate | >= 0 < 5.17 | 5.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i.
ghsa_unreviewed·2026-08-12
CVE-2026-18683 [HIGH] CWE-78 IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i.
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.
GHSA
Weblate: Arbitrary File Read via Symlink
ghsa·2026-04-16
CVE-2026-34242 [HIGH] CWE-200 Weblate: Arbitrary File Read via Symlink
Weblate: Arbitrary File Read via Symlink
### Impact
The ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository.
### Patches
* https://github.com/WeblateOrg/weblate/pull/18683
### References
Thanks to @DavidCarliez for reporting this vulnerability via GitHub.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-0968 libssh: libssh: Denial of Service due to malformed SFTP message
bugzilla·2026-02-04·CVSS 3.1
CVE-2026-0968 [LOW] CVE-2026-0968 libssh: libssh: Denial of Service due to malformed SFTP message
CVE-2026-0968 libssh: libssh: Denial of Service due to malformed SFTP message
A malicious SFTP server can send malformed longname field of the
`SSH_FXP_NAME` message (file listing). Due to the missing NULL check,
the libssh could read beyond the buffer bounds on heap, causing
unexpected behavior or crashes.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:18160 https://access.redhat.com/errata/RHSA-2026:18160
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:18683 https://access.redhat.com/errata/RHSA-2026:18683
Bugzilla
CVE-2026-0964 libssh: Improper sanitation of paths received from SCP servers
bugzilla·2026-02-04·CVSS 5.9
CVE-2026-0964 [MEDIUM] CVE-2026-0964 libssh: Improper sanitation of paths received from SCP servers
CVE-2026-0964 libssh: Improper sanitation of paths received from SCP servers
A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory.
This could be misused to create malicious executable or configuration
files and make the user execute them under specific consequences.
This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:18160 https://access.redhat.com/errata/RHSA-2026:18160
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:18683 https://access.redhat.com/errata/RHSA-2026:18683
Bugzilla
CVE-2025-4878 libssh: Use of uninitialized variable in privatekey_from_file()
bugzilla·2025-07-03·CVSS 3.6
CVE-2025-4878 [LOW] CVE-2025-4878 libssh: Use of uninitialized variable in privatekey_from_file()
CVE-2025-4878 libssh: Use of uninitialized variable in privatekey_from_file()
The privatekey_from_file() uses an uninitialized variable under certain conditions, such as if the file specified by the filename argument doesn't exist. This causes the code to return an invalid private key. This defect, in turn, might cause signing failure. The bug might also cause a Use-After-Free or corrupt the heap. Note that privatekey_from_file() is a deprecated function and shouldn't be used anymore!
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:18683 https://access.redhat.com/errata/RHSA-2026:18683
Bugzilla
CVE-2025-4877 libssh: Write beyond bounds in binary to base64 conversion functions
bugzilla·2025-07-03·CVSS 4.5
CVE-2025-4877 [MEDIUM] CVE-2025-4877 libssh: Write beyond bounds in binary to base64 conversion functions
CVE-2025-4877 libssh: Write beyond bounds in binary to base64 conversion functions
bin_to_base64() (src/base64.c) can experience an integer overflow and subsequent under allocation, leading to a write beyond bounds. The bug can occur only in 32-bit builds. The only problematic use case is ssh_get_fingerprint_hash() in case the API is (mis)used and a libssh consumer passes in an unexpectedly large input buffer. As a mitigation, the function bin_to_base64() is adjusted to not allow inputs larger than 256MB, which is aligned with other functions that process user input.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:18683 https://access.redhat.com/errata/RHSA-2026:18683
2026-08-12
Published