CVE-2026-6544
CVE-2026-6544 is a medium-severity vulnerability in Ibm Concert with a CVSS 3.x base score of 6.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-552.
Key facts
- Severity: Medium (CVSS 3.x base score 6.2)
- EPSS exploit prediction: 0% (2nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-552
- Affected product: Ibm Concert
- Published:
- Last modified:
Description
IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
Frequently asked questions
- What is CVE-2026-6544?
- IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
- How severe is CVE-2026-6544?
- CVE-2026-6544 has a CVSS 3.x base score of 6.2, rated medium severity. It is exploitable over local access with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-6544 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (2nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-6544?
- CVE-2026-6544 affects Ibm Concert. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-6544?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-6544 published?
- CVE-2026-6544 was published on 2026-09-24 and last updated on 2026-09-28.
References
Affected products (1)
- cpe:2.3:a:ibm:concert:*:*:*:*:*:*:*:*
More vulnerabilities in Ibm Concert
- CVE-2026-6928 — Critical (CVSS 9.8): IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can…
- CVE-2026-6730 — Critical (CVSS 9.8): IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user…
- CVE-2026-6721 — Critical (CVSS 9.8): IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is…
- CVE-2026-3627 — Critical (CVSS 9.1): IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL…
- CVE-2025-33015 — High (CVSS 8.8): IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file…
- CVE-2026-6935 — High (CVSS 7.8): IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or…
All CVEs affecting Ibm Concert →
Other CWE-552 (Files or Directories Accessible to External Parties) vulnerabilities
- CVE-2026-71379 — Critical (CVSS 10.0): The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted…
- CVE-2025-41240 — Critical (CVSS 10.0): Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located…
- CVE-2024-56731 — Critical (CVSS 10.0): Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the…
- CVE-2024-6209 — Critical (CVSS 10.0): Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series…
- CVE-2025-14771 — Critical (CVSS 9.9): Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus:…
- CVE-2024-39931 — Critical (CVSS 9.9): Gogs through 0.13.0 allows deletion of internal files.
Browse all CWE-552 (Files or Directories Accessible to External Parties) vulnerabilities →