IBM Doc Offline <1.5.0: Remote ACE via Log Injection
CVE-2026-17481 Published on August 13, 2026
IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs.
Vulnerability Analysis
Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
Weakness Type
Improper Output Neutralization for Logs
The software does not neutralize or incorrectly neutralizes output that is written to logs.
Products Associated with CVE-2026-17481
Want to know whenever a new CVE is published for IBM Documentation Offline? stack.watch will email you.
Affected Versions
IBM Documentation Offline:- Version 1.0.0, <= 1.4.1 is affected.