← Back to search

CVE-2026-6721

9.8 CRITICAL

Published 2026-09-23 · Updated 2026-09-28

AI risk analysis

Summary
This vulnerability allows unauthenticated attackers to execute arbitrary commands on the underlying system by crafting input that is incorporated into OS commands, leading to potential remote code execution with the privileges of the affected application.
Exploitability
Exploitation is relatively straightforward as it requires only unauthenticated access and the ability to supply crafted input, making it a significant risk.
Blast radius
If exploited, this could result in complete system compromise, allowing attackers to gain full control over the affected system and potentially the entire network.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to IBM Concert 3.0.1 or later.
rceunauthos-command-injection

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Vendors

ibm, linux

Products

concert, linux kernel

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.