CVE-2026-17472: Multiple Vulnerabilities in IBM Concert Software
Published Sep 22, 2026
·Updated
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
Other sources
IBM Concert could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
— IBM
Affected Software
1 affected component
IBM Concert Software<=1.0.0-3.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Concert Softwareto a version that resolves this vulnerability.Fixed in 3.0.1.1
Event History
Sep 22, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker must be remotely authenticated to IBM Concert Software.
2
What could a successful attacker do?
A successful attacker could access or modify resources they are not authorized to use because of wildcard use in RBAC permission definitions.