Junglewise Threat Intelligence

CVE-2026-4051: IBM Engineering Lifecycle Management RCE in Jazz Foundation

CVE-2026-4051 · Severity: high · CVSS 7.2 · Published 2026-05-26

Technologies: IBM Engineering Lifecycle Management - Jazz Foundation. Vendors: IBM.

Executive brief

IBM Engineering Lifecycle Management, a suite of tools used by organizations to manage the software development lifecycle, is vulnerable to a security flaw that could allow an administrator to execute unauthorized commands on the server. While the attack requires high-level administrative privileges, a successful exploit could lead to a full system takeover, data theft, or disruption of the development environment. Organizations should apply the latest interim fixes to secure their installations.

Technical details

A remote code execution (RCE) vulnerability exists in the Jazz Foundation component of IBM Engineering Lifecycle Management. The flaw is categorized as CWE-749 (Exposed Dangerous Method or Function), where a specific method is accessible over the network without sufficient access control restrictions. An attacker with administrative privileges can invoke this method to execute arbitrary code on the underlying server. The vulnerability affects versions 7.0.3, 7.1.0, and 7.2.0. IBM has released remediation in the form of Interim Fixes (iFix022 for 7.0.3, iFix010 for 7.1.0, and iFix002 for 7.2.0).

Affected products

  • IBM Engineering Lifecycle Management - Jazz Foundation 7.0.3 through iFix021, 7.1.0 through iFix009, 7.2.0 through iFix001

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory
  • 2026-05-26: patched

References

Related threats