Junglewise Threat Intelligence

CVE-2026-16426: IBM Concert server-side request forgery

CVE-2026-16426 · Severity: medium · CVSS 6.5 · Published 2026-09-22

Technologies: IBM Concert. Vendors: IBM.

Executive brief

IBM Concert is business software that handles workflow and application integration. A server-side request forgery vulnerability allows authenticated users to send unauthorized network requests from the system, enabling attackers to enumerate internal networks, access restricted resources, or launch further attacks on connected systems.

Technical details

A server-side request forgery (SSRF) vulnerability in IBM Concert versions 1.0.0 through 3.0.0 allows authenticated attackers to craft requests that the system processes on their behalf. This permits network enumeration and can serve as a pivot point for lateral movement or access to internal services. The vulnerability requires prior authentication to exploit.

Affected products

  • IBM Concert 1.0.0 through 3.0.0

Timeline

  • 2026-09-22: disclosed

References

Related threats