CVE-2026-6544Medium· 6.2▾ SunlitIBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-15915Medium· 6.2IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.
CVE-2026-6935High· 7.8IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution
CVE-2026-6928Critical· 9.8IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed
CVE-2026-6730Critical· 9.8IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking
CVE-2026-6794High· 7.8IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management
CVE-2026-6925Medium· 5.3IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system