---
id: CVE-2026-6721
title: >-
  IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can
  supply specially crafted input that is incorporated into OS commands,
  resulting in arbitrary command execution on the underlying system
summary: >-
  IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can
  supply specially crafted input that is incorporated into OS commands,
  resulting in arbitrary command execution on the underlying system. Successful
  exploitatio…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: IBM
product: Concert
affected:
  - Concert >= 1.0.0 <= 3.0.0
published: '2026-09-23'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T04:17:38.660'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6721'
references:
  - url: 'https://www.ibm.com/support/pages/node/7288830'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-24T14:09:12.842416Z'
epss: 0.01449
epssPercentile: 0.72236
ingestedAt: '2026-09-23T21:33:13.532Z'
---

## Overview

IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
