Junglewise Threat Intelligence

CVE-2026-3686: IBM Cloud Pak for Data System denial of service

CVE-2026-3686 · Severity: medium · CVSS 6.2 · Published 2026-08-28

Executive brief

IBM Cloud Pak for Data System is an enterprise analytics platform used to store, manage, and analyze business data. A vulnerability in versions 11.3.0.2 through Interim Fix 001 allows an attacker to exhaust system resources and cause a denial of service, preventing legitimate users from accessing the platform and its analytics capabilities.

Technical details

This vulnerability is a resource exhaustion denial of service (DoS) caused by improper limitation of resources in IBM Cloud Pak for Data System. The vulnerability affects versions 11.3.0.2 through Interim Fix 001. An attacker can trigger the resource exhaustion condition to consume excessive system resources, causing the service to become unavailable. The attack likely requires network access to the affected system. IBM has released patches to address this issue.

Affected products

  • IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001

Timeline

  • 2026-08-28: disclosed

References

Related threats