Junglewise Threat Intelligence

CVE-2026-5065: IBM Controller hard-coded credentials

CVE-2026-5065 · Severity: high · CVSS 8.8 · Published 2026-05-27

Vendors: IBM.

Executive brief

IBM Controller, a financial consolidation and reporting solution, contains hard-coded credentials and cryptographic keys. An attacker with basic network access could use these fixed credentials to bypass authentication, intercept communications, or decrypt sensitive internal data. This could lead to unauthorized access to financial records or a complete compromise of the application's integrity.

Technical details

IBM Controller is vulnerable to the use of hard-coded credentials (CWE-798). The software contains fixed passwords or cryptographic keys within its code or configuration files that are used for inbound authentication, communication with external components, and the encryption of internal data. An authenticated attacker with low privileges can leverage these static credentials over the network to gain unauthorized access to sensitive functions or data. The vulnerability is present in versions 11.0.1, 11.1.0, 11.1.1, and 11.1.2. IBM has released version 11.1.3 to remediate this issue.

Affected products

  • IBM Controller 11.0.1, 11.1.0, 11.1.1, 11.1.2

Timeline

  • 2026-05-15: advisory: Initial publication by IBM
  • 2026-05-27: disclosed: NVD publication date

References