Skip to content
ibmCVE-2026-6327

IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

Medium4.3CVE-2026-6327 · Published Sep 23, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Concert
Vendor
>= 1.0.0, <= 3.0.0No fix yet
Details and references

IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Severity from
no source yet
Weakness
CWE-117

More ibm advisories

All

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.