HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-6935 — IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully ...

·Source: NIST NVD

Updated:

Executive Summary

IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.

Analysis

IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code. CVSS Score: 7.8. Published: 2026-09-23T21:17:02.553.

Indicators of Compromise (1)

CVE (1)
CVE-2026-6935
Source Attribution

Originally published by NIST NVD on Sep 23, 2026. Verified by: NIST.

Related Threats