MEDIUM
Multiple Vulnerabilities in IBM Concert Software
Published Sep 24, 2026
6.2
MEDIUMCVSS 3.1
EPSS 0.12%
Description
IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<=3.0.0
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1
Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow installation instructions https://www.ibm.com/docs/en/concert depending on the type of deployment.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86009 Advisory
- https://www.ibm.com/support/pages/node/7288830 vendor-advisorypatch
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86009 | Advisory | |
| https://www.ibm.com/support/pages/node/7288830 | vendor-advisorypatch |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Sep 24, 2026
Updated Sep 24, 2026
Reserved Apr 17, 2026
Link CVE-2026-6544
CISA Vulnrichment
Updated Sep 24, 2026
ENISA EUVD
EUVD-2026-86009 Assigner ibm
Published Sep 24, 2026
Updated Sep 24, 2026
Exploited since n/a
Link EUVD-2026-86009