ibmCVE-2026-6928
IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed.
Critical9.8CVE-2026-6928 · Published Sep 23, 2026 · updated Sep 25, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Concert Vendor | >= 1.0.0, <= 3.0.0 | No fix yet |
Details and references
IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- no source yet
- Weakness
- CWE-416