IBM Doc Offline <1.5.0: Remote ACE via Log Injection
CVE-2026-17481 Published on August 13, 2026

IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

Improper Output Neutralization for Logs

The software does not neutralize or incorrectly neutralizes output that is written to logs.


Products Associated with CVE-2026-17481

Want to know whenever a new CVE is published for IBM Documentation Offline? stack.watch will email you.

 

Affected Versions

IBM Documentation Offline: