Description
IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Published: 2026-09-22
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Server-side request forgery ( attacker to cause the system to send unauthorized HTTP requests
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a server‑side request forgery that allows an authenticated user to instruct the IBM Concert server to make arbitrary outbound HTTP requests, potentially exposing internal network resources or facilitating further attacks. The flaw requires valid credentials but does not necessarily grant privileged system access; however, the ability to reach arbitrary endpoints can be leveraged to enumerate a network, exfiltrate data, or pivot to other services.

Affected Systems

IBM Concert Software versions 1.0.0 through 3.0.0 are affected. The recommendation from IBM is to upgrade to version 3.0.1.1 to resolve the issue.

Risk and Exploitability

The CVSS score for this vulnerability is 6.5, indicating moderate severity. EPSS is not available, so exact exploitation prevalence is uncertain, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires authentication to the Concert system, but once authenticated, the attacker can carry out request forgery that may lead to network enumeration or other malicious activities.

Generated by OpenCVE AI on September 22, 2026 at 22:27 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1 Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow  installation instructions https://www.ibm.com/docs/en/concert  depending on the type of deployment.


OpenCVE Recommended Actions

  • Upgrade IBM Concert Software to version 3.0.1.1 promptly to eliminate the SSRF flaw
  • Limit access so that only trusted administrators have permissions to features that trigger outbound HTTP calls
  • Implement outbound firewall rules or proxy filters to restrict the Concert server from contacting unintended external destinations

Generated by OpenCVE AI on September 22, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Title Multiple Vulnerabilities in IBM Concert Software
First Time appeared Ibm
Ibm concert
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:3.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm concert
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T21:22:33.718Z

Reserved: 2026-07-20T23:45:54.571Z

Link: CVE-2026-16426

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:06.797

Modified: 2026-09-22T22:17:06.797

Link: CVE-2026-16426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:30:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)