OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-17472

CRITICAL · CVSS 9.6 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

IBM Concert versions 1.0.0 through 3.0.0 are vulnerable to a critical access control flaw that allows remote authenticated attackers to exploit wildcard usage in Role-Based Access Control (RBAC) permissions, potentially granting them unauthorized access to or modification of sensitive resources. Organizations using these versions should prioritize patching or mitigating this vulnerability to prevent potential data breaches or unauthorized modifications.

CVE
CVE-2026-17472
Severity
CRITICAL
CVSS
9.6
EPSS
0.30%

Original NVD Description

IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.