Junglewise Threat Intelligence

CVE-2026-17472: IBM Concert unauthorized resource access via RBAC wildcard

CVE-2026-17472 · Severity: critical · CVSS 9.6 · Published 2026-09-22

Technologies: IBM Concert. Vendors: IBM.

Executive brief

IBM Concert is a software platform used for enterprise management and automation. Versions 1.0.0 through 3.0.0 contain a flaw in how role-based access control permissions are defined using wildcards, allowing an authenticated attacker to access or modify resources they should not have permission to reach. An attacker with valid credentials could exploit this to gain unauthorized access to sensitive data or modify critical configurations.

Technical details

The vulnerability exists in IBM Concert's RBAC permission evaluation logic where wildcard patterns in permission definitions are improperly handled, allowing privilege escalation. An authenticated network attacker can craft requests that bypass intended access restrictions through wildcard matching exploitation. The flaw affects versions 1.0.0 through 3.0.0 and is addressed in version 3.0.1.1 and later.

Affected products

  • IBM Concert 1.0.0 through 3.0.0

Timeline

  • 2026-09-22: disclosed

References

Related threats