{"id":"CVE-2026-6721","published":"2026-09-23T21:17:01.927","lastModified":"2026-09-28T20:45:56.910","description":"IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":["ibm","linux"],"products":["concert","linux kernel"],"references":[{"url":"https://www.ibm.com/support/pages/node/7288830","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows unauthenticated attackers to execute arbitrary commands on the underlying system by crafting input that is incorporated into OS commands, leading to potential remote code execution with the privileges of the affected application.","exploitability":"Exploitation is relatively straightforward as it requires only unauthenticated access and the ability to supply crafted input, making it a significant risk.","blast_radius":"If exploited, this could result in complete system compromise, allowing attackers to gain full control over the affected system and potentially the entire network.","remediation":"Upgrade to IBM Concert 3.0.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","unauth","os-command-injection"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:51:36.703Z"}}