Junglewise Threat Intelligence

CVE-2026-15915: IBM Concert information disclosure in build context copying

CVE-2026-15915 · Severity: medium · CVSS 6.2 · Published 2026-09-22

Technologies: IBM Concert. Vendors: IBM.

Executive brief

IBM Concert is a containerization tool used to package applications into container images. Versions 1.0.0 through 3.0.0 recursively copy build context directories into container images without proper filtering, potentially exposing sensitive files like credentials or private keys to local attackers who can access the resulting container images.

Technical details

IBM Concert fails to sanitize build context during recursive directory copying into container images, allowing sensitive information to be included in the final image layer. A local attacker with access to the container image filesystem or registry can extract unintended secrets. The vulnerability affects versions 1.0.0 through 3.0.0 and requires local access to the container environment.

Affected products

  • IBM Concert 1.0.0 through 3.0.0

Timeline

  • 2026-09-22: disclosed

References

Related threats