PatchSiren cyber security CVE debrief
CVE-2026-3660 IBM CVE debrief
IBM Engineering Lifecycle Management (ELM) versions 7.0.3, 7.1.0, and 7.2.0 contain a critical authentication bypass vulnerability. An unauthenticated remote attacker can modify server property files to gain unauthorized administrative access to the application. The vulnerability is rated CVSS 3.1 9.8 (Critical) with network attack vector, low attack complexity, and no privileges or user interaction required. The weakness is categorized as CWE-863 (Incorrect Authorization). IBM has published a security bulletin with remediation guidance. No known exploitation in ransomware campaigns has been reported.
- Vendor
- IBM
- Product
- Engineering Lifecycle Management
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-05-26
Who should care
Organizations running IBM Engineering Lifecycle Management 7.0.3, 7.1.0, or 7.2.0 for software or systems engineering lifecycle management, particularly those with externally accessible deployments. Security teams responsible for application security in engineering and development environments. Compliance officers tracking critical vulnerability remediation timelines.
Technical summary
The vulnerability exists in IBM Engineering Lifecycle Management versions 7.0.3, 7.1.0, and 7.2.0. An unauthenticated attacker can remotely update server property files, which control application configuration and access controls. By manipulating these files, the attacker can escalate privileges and gain unauthorized access to the application. The attack requires no authentication, no user interaction, and is exploitable over the network with low complexity. The CVSS 3.1 score of 9.8 reflects complete confidentiality, integrity, and availability impact.
Defensive priority
critical
Recommended defensive actions
- Apply IBM's security update for Engineering Lifecycle Management 7.0.3, 7.1.0, or 7.2.0 as referenced in the vendor security bulletin
- Restrict network access to ELM administrative interfaces to trusted hosts only until patching is complete
- Monitor application logs for unauthorized property file modifications or unexpected configuration changes
- Verify integrity of server property files and restore from known-good backups if unauthorized changes are detected
- Review user access logs for anomalous administrative activity following the disclosure date
Evidence notes
CVE published 2026-05-26T19:16:27.707Z; modified 2026-05-26T21:16:36.883Z. IBM PSIRT reference confirmed. CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. CWE-863 identified. NVD status: Undergoing Analysis.
Official resources
-
CVE-2026-3660 CVE record
CVE.org
-
CVE-2026-3660 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-05-26