Description
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory.
Published: 2026-08-13
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Documentation Offline versions 1.0.0 through 1.4.1 include an improper limitation of a pathname that allows a remote attacker to read arbitrary files inside the installation directory, which can lead to information disclosure. The vulnerability is classified as CWE‑22 (Path Traversal). The information disclosure exposed by reading files may enable further exploitation such as session forgery or remote code execution as noted in the advisory title.

Affected Systems

The affected product is IBM Documentation Offline. All releases from 1.0.0 through 1.4.1 are vulnerable; the company recommends upgrading to the latest available release, 1.5.1.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity for this flaw, and a remote attacker can exploit it without any local access. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. Because the flaw is reachable via network, it can be triggered by unauthenticated remote requests and causes a loss of confidentiality, potentially leading to session compromise or code execution.

Generated by OpenCVE AI on August 13, 2026 at 22:43 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Documentation Offline1.0.0 - 1.4.1Download and install latest release (1.5.1)


OpenCVE Recommended Actions

  • Download and install IBM Documentation Offline 1.5.1, the release that includes the fix for this path traversal issue.
  • If an immediate patch is not possible, isolate affected systems from the network to prevent remote exploitation until the upgrade can occur.
  • Add monitoring for abnormal file access or unexpected user session activity to detect potential exploitation attempts.

Generated by OpenCVE AI on August 13, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory.
Title IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
First Time appeared Ibm
Ibm documentation Offline
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:documentation_offline:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:documentation_offline:1.4.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm documentation Offline
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Documentation Offline
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:39:13.278Z

Reserved: 2026-07-25T21:23:18.220Z

Link: CVE-2026-17473

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:43.067

Modified: 2026-08-13T21:17:43.067

Link: CVE-2026-17473

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:30:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')