CVE-2026-6327Medium· 4.3▾ SunlitIBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6928Critical· 9.8IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed
CVE-2026-6935High· 7.8IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution
CVE-2026-6730Critical· 9.8IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking
CVE-2026-6794High· 7.8IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management
CVE-2026-6925Medium· 5.3IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system
CVE-2026-6718Medium· 6.2IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of application files.