CVE-2026-3626Medium· 5.3▾ SunlitIBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6928Critical· 9.8IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed
CVE-2026-6935High· 7.8IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution
CVE-2026-6730Critical· 9.8IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking
CVE-2026-6794High· 7.8IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management
CVE-2026-6925Medium· 5.3IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system
CVE-2026-6718Medium· 6.2IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of application files.