HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-6935 — IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully ...
·Source: NIST NVD
Updated:
Executive Summary
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.
Analysis
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code. CVSS Score: 7.8. Published: 2026-09-23T21:17:02.553.