---
id: CVE-2026-8862
title: >-
  IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are
  hardcoded in the application source code, allowing unauthorized access to the
  container registry
summary: >-
  IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are
  hardcoded in the application source code, allowing unauthorized access to the
  container registry. The exposed secret enables attackers to pull private
  contain…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-522
vendor: ibm
product: netezza_performance_server
affected:
  - netezza_performance_server < 11.3.1.3
patched:
  - netezza_performance_server 11.3.1.3
published: '2026-09-03'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T20:38:54.823'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8862'
references:
  - url: 'https://www.ibm.com/support/pages/node/7284359'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00394
epssPercentile: 0.30737
ingestedAt: '2026-09-08T15:33:26.958Z'
---

## Overview

IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information.

## Affected

- `netezza_performance_server < 11.3.1.3`

## Remediation

Upgrade past the affected range:

- `netezza_performance_server 11.3.1.3`
