CVE-2025-36178: Input Validation
Published Sep 17, 2026
·Updated
IBM Controller could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size.
Affected Software
2 affected components
IBM Controller<=11.0.0 - 11.0.1 FP7
IBM Controller<=11.1.0 - 11.1.3 FP1
Event History
Sep 17, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Does exploitation require an authenticated account?
Yes. The issue is described as exploitable by an authenticated user.
2
What should validation testing focus on?
Testing should focus on client-side handling of file-size input, where validation can be bypassed.