CVE-2026-4051: IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Server Post-Auth Remote Code Execution
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.0.3Patch iFix022 - Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.1.0Patch iFix010 - Upgrade
Upgrade
IBM Engineering Lifecycle Management - Jazz Foundationto a version that resolves this vulnerability.Fixed in 7.2.0Patch iFix002
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4051?
The severity of CVE-2026-4051 is rated high with a score of 7.2.
How do I fix CVE-2026-4051?
To fix CVE-2026-4051, upgrade to the appropriate iFix as specified in IBM's remediation guidance.
What products are affected by CVE-2026-4051?
CVE-2026-4051 affects IBM Engineering Lifecycle Management versions 7.0.3, 7.1.0, and 7.2.0.
What type of vulnerability is CVE-2026-4051?
CVE-2026-4051 is a server post-authentication remote code execution vulnerability.
Who can exploit CVE-2026-4051?
CVE-2026-4051 can be exploited by an attacker with administrative privileges.