CVE-2026-6544 MEDIUM

CVE-2026-6544: Multiple Vulnerabilities in IBM Concert Software

Vendor Ibm
Product Concert
Weakness CWE-552 · Files accessible externally
Published September 24, 2026
Last update September 24, 2026

CVSS base score

6.2/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.

Key dates

02Disclosure timeline

September 24, 2026 CVE published
September 24, 2026 Record updated