critical · CVSS v3 9.6
CVE-2026-17472
IBM Concert 1.0.0-3.0.0 allows a remote authenticated attacker to access or modify resources they should not have permission for due to wild
Overview
IBM Concert 1.0.0-3.0.0 allows a remote authenticated attacker to access or modify resources they should not have permission for due to wildcard RBAC definitions. This can lead to unauthorized data exposure or tampering. The flaw is critical and requires immediate attention.
Description
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
Impact
Confidentiality and integrity of data managed by Concert are at risk. Authenticated users could read or alter resources beyond their scope, potentially affecting business processes and regulatory compliance. Availability may be impacted if attackers modify configuration or disrupt services.
Remediation
Apply the latest security patch or upgrade to a version that removes wildcard RBAC support. Review and tighten RBAC rules, ensuring no wildcard permissions are granted. Enforce least-privilege and monitor for anomalous access patterns. Consider disabling or restricting wildcard usage in custom roles.
Risk context
The CVE is rated critical with a CVSS v3 score of 9.6. No EPSS data is available, but the severity indicates a high likelihood of exploitation in environments where IBM Concert is deployed.
Affected products
- IBM Concert 1.0.0
- IBM Concert 2.0.0
- IBM Concert 3.0.0
Scores
- Severity
- critical
- CVSS v2
- 8.5
- CVSS v3
- 9.6
- CVSS v4
- —
- EPSS
- —