CVE-2026-17472 is a vulnerability in IBM Concert
Published on September 22, 2026
Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
Vulnerability Analysis
CVE-2026-17472 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Improper Privilege Management
The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Products Associated with CVE-2026-17472
Want to know whenever a new CVE is published for IBM Concert? stack.watch will email you.
Affected Versions
IBM Concert:- Version 1.0.0, <= 3.0.0 is affected.