CVE-2026-6721 PUBLISHED

Multiple Vulnerabilities in IBM Concert Software

Assigner: ibm
Reserved: 20.04.2026 Published: 23.09.2026 Updated: 25.09.2026

IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor IBM
Product Concert
Versions
  • affected from 1.0.0 to 3.0.0 (incl.)

Solutions

IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 3.0.1.1

Download IBM Concert Software 3.0.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow  installation instructions https://www.ibm.com/docs/en/concert  depending on the type of deployment.

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE