CVE-2026-15915: Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.
Other sources
IBM Concert could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Concert Softwareto a version that resolves this vulnerability.Fixed in 3.0.1.1
Event History
Frequently Asked Questions
Which deployments are affected?
IBM Concert versions 1.0.0 through 3.0.0 are affected.
What access does an attacker need?
An attacker needs local access. No privileges or user interaction are required according to the supplied CVSS vector.
What information could be exposed?
Sensitive information in build context directories may be copied recursively into container images and become accessible to a local attacker.