IBM Documentation Offline 1.0.0-1.4.1: Hardcoded key allows session token forge
CVE-2026-17468 Published on August 13, 2026
IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic key.
Vulnerability Analysis
CVE-2026-17468 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and no impact on availability.
Weakness Type
Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
Products Associated with CVE-2026-17468
Want to know whenever a new CVE is published for IBM Documentation Offline? stack.watch will email you.
Affected Versions
IBM Documentation Offline:- Version 1.0.0, <= 1.4.1 is affected.