Junglewise Threat Intelligence

CVE-2026-13463: IBM Cloud Pak System information disclosure in log files

CVE-2026-13463 · Severity: high · CVSS 7.5 · Published 2026-07-28

Vendors: IBM.

Executive brief

IBM Cloud Pak System, a platform for managing hybrid cloud environments, is affected by a security flaw that could expose sensitive credentials. An attacker with local access to the system could read these credentials from log files, potentially leading to unauthorized access to other parts of the infrastructure. This issue stems from a component called IBM Storage Protect and could compromise the confidentiality of customer data and system operations.

Technical details

IBM Cloud Pak System is vulnerable to information disclosure due to the improper handling of credentials within its logging mechanisms. The vulnerability, originating in the IBM Storage Protect component, results in sensitive credentials being written in plain text to system log files (CWE-798). A local attacker with access to these log files can extract the credentials to gain unauthorized elevated access. While the CVSS vector provided by the vendor indicates a network attack vector, the descriptive text specifies a local attacker. The issue is addressed in IBM Cloud Pak System version 2.3.5.1.

Affected products

  • IBM Cloud Pak System 2.3.5.0
  • IBM Cloud Pak System Software 2.3.5.0
  • IBM Cloud Pak System Software Suite 2.3.5.0
  • IBM Storage Protect Not specified

Timeline

  • 2026-07-09: disclosed: Initial publication by IBM
  • 2026-07-28: advisory: NVD publication date
  • 2026-07-28: patched: Fix available in version 2.3.5.1

References