Junglewise Threat Intelligence

CVE-2026-5935: IBM TSSC and TS4500 IMC OS command injection

CVE-2026-5935 · Severity: high · CVSS 7.3 · Published 2026-04-23

Vendors: IBM.

Executive brief

IBM Total Storage Service Console (TSSC) and TS4500 IMC, which are used to manage and service enterprise tape storage systems, contain a security vulnerability. An unauthenticated attacker could remotely execute commands on the system with standard user privileges. This could lead to unauthorized access to storage management functions or serve as a foothold for further attacks on the storage network.

Technical details

An OS command injection vulnerability (CWE-78) exists in the IBM Total Storage Service Console (TSSC) and TS4500 IMC due to improper validation of user-supplied input at HTTP/HTTPS endpoints. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the affected web interface. Successful exploitation allows the execution of arbitrary operating system commands with the privileges of a normal user. IBM has released patches (e.g., 9.X.X_FixOSCommandInjection_2026-04-06) and recommends upgrading to versions 9.4.31 or 9.6.15.

Affected products

  • IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6

Timeline

  • 2026-04-20: disclosed: Initial publication by IBM
  • 2026-04-22: advisory: NVD publication date
  • 2026-05-18: other: NVD last modified date

References