PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3660 IBM CVE debrief

IBM Engineering Lifecycle Management (ELM) versions 7.0.3, 7.1.0, and 7.2.0 contain a critical authentication bypass vulnerability. An unauthenticated remote attacker can modify server property files to gain unauthorized administrative access to the application. The vulnerability is rated CVSS 3.1 9.8 (Critical) with network attack vector, low attack complexity, and no privileges or user interaction required. The weakness is categorized as CWE-863 (Incorrect Authorization). IBM has published a security bulletin with remediation guidance. No known exploitation in ransomware campaigns has been reported.

Vendor
IBM
Product
Engineering Lifecycle Management
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-05-26
Advisory published
2026-05-26
Advisory updated
2026-05-26

Who should care

Organizations running IBM Engineering Lifecycle Management 7.0.3, 7.1.0, or 7.2.0 for software or systems engineering lifecycle management, particularly those with externally accessible deployments. Security teams responsible for application security in engineering and development environments. Compliance officers tracking critical vulnerability remediation timelines.

Technical summary

The vulnerability exists in IBM Engineering Lifecycle Management versions 7.0.3, 7.1.0, and 7.2.0. An unauthenticated attacker can remotely update server property files, which control application configuration and access controls. By manipulating these files, the attacker can escalate privileges and gain unauthorized access to the application. The attack requires no authentication, no user interaction, and is exploitable over the network with low complexity. The CVSS 3.1 score of 9.8 reflects complete confidentiality, integrity, and availability impact.

Defensive priority

critical

Recommended defensive actions

  • Apply IBM's security update for Engineering Lifecycle Management 7.0.3, 7.1.0, or 7.2.0 as referenced in the vendor security bulletin
  • Restrict network access to ELM administrative interfaces to trusted hosts only until patching is complete
  • Monitor application logs for unauthorized property file modifications or unexpected configuration changes
  • Verify integrity of server property files and restore from known-good backups if unauthorized changes are detected
  • Review user access logs for anomalous administrative activity following the disclosure date

Evidence notes

CVE published 2026-05-26T19:16:27.707Z; modified 2026-05-26T21:16:36.883Z. IBM PSIRT reference confirmed. CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. CWE-863 identified. NVD status: Undergoing Analysis.

Official resources

2026-05-26