CVE-2026-6935
EUVD-2026-8567023.09.2026, 21:17
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| ibm | concert | 1.0.0 ≤ 𝑥 ≤ 3.0.0 | CNA |
Common Weakness Enumeration