OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-6721 (CVSS 9.8)

NVD · officialPublished Sep 23, 2026Risk 50/100EPSS 1.4%

IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.

CVSS
9.8
AV:NetworkAC:LowPR:NoneUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source