Back

HIGH

Multiple Vulnerabilities in IBM Concert Software

Published Sep 23, 2026

Description

IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1

Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow  installation instructions https://www.ibm.com/docs/en/concert  depending on the type of deployment.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ibm
Published Sep 23, 2026
Updated Sep 25, 2026
Reserved Apr 23, 2026

CISA Vulnrichment

Updated Sep 24, 2026

NVD

Status Received
Modified Sep 23, 2026

Red Hat

No data

ENISA EUVD

Assigner ibm
Published Sep 23, 2026
Updated Sep 25, 2026

GitHub

No data