IBM Documentation Offline 1.0.0-1.4.1: Hardcoded key allows session token forge
CVE-2026-17468 Published on August 13, 2026

IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-17468 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
LOW
Availability Impact:
NONE

Weakness Type

Use of Hard-coded Cryptographic Key

The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.


Products Associated with CVE-2026-17468

Want to know whenever a new CVE is published for IBM Documentation Offline? stack.watch will email you.

 

Affected Versions

IBM Documentation Offline: