Description
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
Published: 2026-09-22
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Remote authenticated access to unauthorized resources
Action: Apply Patch
AI Analysis

Impact

The vulnerability, identified as a CWE-269 weakness (Improper Privilege Management), stems from the use of wildcard entries in role‑based access control (RBAC) permission definitions in IBM Concert Software. A malicious actor possessing valid credentials can exploit this flaw to view or alter data and settings that the attacker should not be able to modify. This results in a loss of data confidentiality, integrity, and potentially system availability if critical configurations are tampered with.

Affected Systems

IBM Concert versions 1.0.0 through 3.0.0 are affected, with the most recent vulnerable release being 3.0.0. Users running any of these versions, regardless of deployment type, are at risk until an upgrade is performed.

Risk and Exploitability

This vulnerability is a CWE-269 weakness involving improper privilege management, and the CVSS score of 9.6 indicates a high severity vulnerability that poses a significant risk to systems in use. While an EPSS score is not available, the lack of listing in the CISA KEV catalog suggests no current widespread exploitation. Nonetheless, the attack requires only an authenticated session, making it realistic for an insider or compromised account to exploit the system. Remediation is recommended promptly to prevent potential data exfiltration or configuration changes.

Generated by OpenCVE AI on September 22, 2026 at 22:51 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1 Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow  installation instructions https://www.ibm.com/docs/en/concert  depending on the type of deployment.


OpenCVE Recommended Actions

  • Upgrade IBM Concert Software to version 3.0.1.1 as recommended by IBM.
  • After upgrading, audit RBAC permission definitions and remove any wildcard entries to enforce least privilege.
  • Conduct a security assessment or run IBM security scanner to confirm that no unauthorized permissions remain.

Generated by OpenCVE AI on September 22, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
Title Multiple Vulnerabilities in IBM Concert Software
First Time appeared Ibm
Ibm concert
Weaknesses CWE-269
CPEs cpe:2.3:a:ibm:concert:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:concert:3.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm concert
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T21:26:50.380Z

Reserved: 2026-07-25T21:12:48.524Z

Link: CVE-2026-17472

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:07.683

Modified: 2026-09-22T22:17:07.683

Link: CVE-2026-17472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T23:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management