{"id":"CVE-2026-6935","published":"2026-09-23T21:17:02.553","lastModified":"2026-09-29T14:00:54.787","description":"IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-427"],"vendors":["ibm","linux"],"products":["concert","linux kernel"],"references":[{"url":"https://www.ibm.com/support/pages/node/7288830","tags":["Patch","Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":null}