IBM Documentation 1.0.0-1.4.1 IP Bind Misconfiguration
CVE-2026-16713 Published on August 13, 2026
IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation server binds to an unrestricted IP address.
Vulnerability Analysis
Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
NONE
Availability Impact:
NONE
Weakness Type
Binding to an Unrestricted IP Address
The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.
Products Associated with CVE-2026-16713
Want to know whenever a new CVE is published for IBM Documentation Offline? stack.watch will email you.
Affected Versions
IBM Documentation Offline:- Version 1.0.0, <= 1.4.1 is affected.