Junglewise Threat Intelligence

CVE-2026-8862: IBM Netezza Software hardcoded credentials in registry

CVE-2026-8862 · Severity: high · CVSS 7.5 · Published 2026-09-03

Technologies: IBM Netezza Performance Server, IBM Netezza Software. Vendors: IBM.

Executive brief

IBM Netezza Software contains hardcoded credentials embedded in its source code that allow unauthorized access to the container registry. An attacker exploiting this flaw can pull private container images, potentially exposing proprietary code, configuration details, and other sensitive business information stored within those images.

Technical details

The vulnerability is a credential exposure flaw where sensitive authentication credentials are hardcoded in the IBM Netezza Software application source code. This allows attackers to authenticate to the container registry without authorization. The exposed credentials enable pulling of private container images, which may contain proprietary code, configuration secrets, and sensitive data. The vulnerability affects Netezza Software versions 11.3.0.3 through Interim Fix 002, and is fixed in version 11.3.1.3. Attack requires network access to the container registry but no prior authentication or user interaction.

Affected products

  • IBM Netezza Software 11.3.0.3 through Interim Fix 002

Timeline

  • 2026-09-03: disclosed
  • 2026: patched: Fixed in version 11.3.1.3

References

Related threats