Junglewise Threat Intelligence

CVE-2026-3660: IBM Engineering Lifecycle Management auth bypass in Jazz Foundation

CVE-2026-3660 · Severity: critical · CVSS 9.8 · Published 2026-05-26

Technologies: IBM Engineering Lifecycle Management - Jazz Foundation. Vendors: IBM.

Executive brief

IBM Engineering Lifecycle Management, a suite used by organizations to manage complex software and systems development, contains a critical security flaw. An unauthenticated attacker can remotely modify server configuration files, which allows them to bypass security controls and gain full unauthorized access to the application. This could lead to the theft of intellectual property, disruption of development workflows, or total compromise of the management platform.

Technical details

An authentication bypass vulnerability exists in the Jazz Foundation component of IBM Engineering Lifecycle Management due to incorrect authorization (CWE-863). The flaw allows a remote, unauthenticated attacker to modify server property files. By manipulating these configuration files, an attacker can escalate privileges or bypass authentication mechanisms entirely to gain unauthorized access to the application. The vulnerability is exploitable over the network with low complexity and requires no user interaction. IBM has released interim fixes (iFixes) to address this issue across versions 7.0.3, 7.1.0, and 7.2.0.

Affected products

  • IBM Engineering Lifecycle Management - Jazz Foundation 7.0.3 through iFix021, 7.1.0 through iFix009, 7.2.0 through iFix001

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory
  • 2026-05-26: patched: Interim fixes released for affected versions.

References

Related threats