CVE-2026-6935
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Concert | 1.0.0 <= 3.0.0 | affected |
Weaknesses
- CWE-427: CWE-427 Uncontrolled Search Path Element
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.