CVE-2026-16426: Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Other sources
IBM Concert is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Concertto a version that resolves this vulnerability.Fixed in 3.0.1.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must be authenticated to IBM Concert Software. The available information does not indicate that unauthenticated attackers can exploit it.
What could exploitation enable?
An authenticated attacker may cause the affected system to send unauthorized requests. This could be used for network enumeration or to facilitate additional attacks.