Junglewise Threat Intelligence

CVE-2024-27253: IBM DOORS Next authentication bypass in Review delete

CVE-2024-27253 · Severity: critical · CVSS 10 · Published 2026-08-12

Vendors: IBM.

Executive brief

IBM DOORS Next is a requirements management platform used by organizations to organize, track, and manage engineering requirements and project documentation. An authenticated user can exploit a vulnerability in the Review delete request function to bypass security controls and perform unauthorized activities they should not have permission to do, potentially compromising data integrity and access controls.

Technical details

The vulnerability is an improper authentication flaw (CWE-287) in the Review delete request function of IBM DOORS Next versions 7.0.3 through 7.0.3 iFix018. An authenticated user with network access to the system can bypass security logic by submitting specially crafted requests to the Review delete endpoint without proper authorization checks. The attack requires authentication and network access, with no additional user interaction needed. An attacker can perform unauthorized activities including viewing sensitive information, modifying records, and deleting reviews. The fix is available via iFix019 or later, and users are advised to upgrade immediately or move to version 7.2.0.

Affected products

  • IBM DOORS Next 7.0.3 through 7.0.3 iFix018

Timeline

  • 2026-08-05: disclosed
  • 2026-08-05: patched: iFix019 or later available

References