PatchSiren

IBM CVE debriefs · Page 7

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM IBM CVE published 2026-08-14

CVE-2026-17227

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command. This vulnerability has a medium severity level with a CVSS score of 5.4. System administrators and security teams should review and apply vendor-provided mitigations or patches, conduct thorough inventory checks, and i [truncated]

MEDIUM IBM CVE published 2026-08-14

CVE-2026-17209

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting. This vulnerability exists in the affected versions, posing a risk to systems that have not been patched. Security teams should review the vulnerability details and assess potential impact on their environments.

CRITICAL IBM CVE published 2026-08-14

CVE-2026-17186

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 are vulnerable to remote CL command execution due to improper neutralization of special elements in a command. This vulnerability, CVE-2026-17186, has a CVSS score of 9.9 and is considered CRITICAL. Organizations using these versions should be aware of the potential for remote code execution and take immediate action to patch or mitigate the vulnerability. The CVE re [truncated]

CRITICAL IBM CVE published 2026-08-14

CVE-2026-17184

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-14T20:16:51.010Z and has not been modified since then. The vulnerability affects IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6, allowing remote code execution due to external control of file name or path, with a CVSS score of 9.8 indicating critical severity. Organizations should prioritize patchi [truncated]

HIGH IBM CVE published 2026-08-14

CVE-2026-16708

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration. This vulnerability affects the system's ability to maintain secure configurations, potentially exposing sensitive information. Security teams should review system configurations and apply necessary updates or mitigations.

HIGH IBM CVE published 2026-08-13

CVE-2026-19483

IBM Storage Scale systems may disclose secrets in log files due to the admin password being logged into the GUI log during Deploy and Upgrade from GUI. Additionally, secrets may be disclosed in information related to exceptions in the IBM Storage Scale Management GUI. This vulnerability has a CVSS score of 7.1, indicating high severity. Affected product deployments should be reviewed, and owners should be [truncated]

CRITICAL IBM CVE published 2026-08-13

CVE-2026-19297

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T21:17:45.870Z and has not been modified since then. This vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.9.6, allowing remote attackers to gain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. Organizations should review their [truncated]

HIGH IBM CVE published 2026-08-13

CVE-2026-18249

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses. This vulnerability poses a significant risk as it could enable attackers to escalate their privileges within the system, potentially leading to unauthorized access and control. The issue is caused by inadequate validation of Java-c [truncated]

HIGH IBM CVE published 2026-08-13

CVE-2026-18193

IBM i 7.6, 7.5, 7.4, and 7.3 are affected by a security vulnerability due to improper validation of user-controlled addresses. This could allow a remote attacker to bypass security restrictions. Organizations should review the CVE record and take necessary actions to prevent potential security breaches. The CVE record was published on 2026-08-13T21:17:44.700Z and has not been modified since then. Evidence [truncated]

HIGH IBM CVE published 2026-08-13

CVE-2026-18101

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T21:17:44.550Z and has not been modified since then. The vulnerability affects IBM i 7.6, 7.5, 7.4, and 7.3 systems, potentially allowing local attackers to gain elevated privileges due to improper management of thread authority swaps. System administrators and security teams managing these system [truncated]

HIGH IBM CVE published 2026-08-13

CVE-2026-17473

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a restricted directory. This vulnerability exists in the IBM Documentation Offline product, which is susceptible to a directory traversal attack. A remote attacker could exploit this vulnerability to read arbitrary files, potentially leading to sensitive informati [truncated]

MEDIUM IBM CVE published 2026-08-13

CVE-2026-17468

IBM Documentation Offline 1.0.0 through 1.4.1 is vulnerable to session token forgery due to a hardcoded cryptographic key. A remote attacker could exploit this vulnerability to forge valid session tokens. This issue affects IBM Documentation Offline users and administrators, who should be aware of the vulnerability and take necessary actions to remediate it. The vulnerability has a medium severity with a [truncated]

HIGH IBM CVE published 2026-08-13

CVE-2026-16722

IBM i 7.6, 7.5, 7.4, and 7.3 are affected by CVE-2026-16722, a high-severity vulnerability due to improper privilege management. This allows remote authenticated attackers to gain unauthorized privileges, with a CVSS score of 8.8. System administrators and users should review and update user privileges, apply patches, and monitor system logs for suspicious activity. Evidence is limited, and further verifi [truncated]

CRITICAL IBM CVE published 2026-08-13

CVE-2026-14525

IBM WebSphere Application Server - Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled. This vulnerability affects organizations using the affected product versions. The CVE record was published on 2026-08-13T20:17:14.250Z and has not been modified since then. The vulnerability has a CVSS score of 9.4 and is classified as CRITICAL. Affected product [truncated]

CRITICAL IBM CVE published 2026-08-12

CVE-2024-27253

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. This vulnerability affects IBM DOORS Next deployments, potentially allowing unauthorized activities. Defenders should assess exposure and prioritize verifying security logic and authentication mechanisms. The CVE record and NVD entry provide limited information [truncated]

HIGH IBM CVE published 2026-08-12

CVE-2026-17110

IBM i 7.6, 7.5, 7.4, and 7.3 are vulnerable to improper privilege management, allowing remote authenticated attackers to execute arbitrary commands and obtain sensitive information. This vulnerability was published on 2026-08-12T18:17:25.717Z and has not been modified since then. Organizations should review their deployments and prioritize patching to prevent potential attacks.

HIGH IBM CVE published 2026-08-12

CVE-2026-16907

IBM i versions 7.3 through 7.6 are affected by CVE-2026-16907, a high-severity vulnerability allowing remote authenticated attackers to execute arbitrary code due to improper bounds checking. This issue requires immediate attention from IBM i administrators and cybersecurity teams to prevent potential code execution. The CVSS score of 7.6 indicates high severity. Published on 2026-08-12 and last modified [truncated]

HIGH IBM CVE published 2026-08-12

CVE-2026-16856

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T18:17:24.277Z and has not been modified since then. The vulnerability exists in IBM i 7.6 and 7.5 due to improper neutralization of special elements used in an OS command. This could allow a local attacker to gain elevated privileges. The CVSS score is 8.8, indicating a high severity vulnerabilit [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-9205

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. The CVE record was published on 2026-08-05T19:17:49.193Z and has not been modified since then. This vulnerability has a CVSS score of 7.4 and is classified as HIGH severity. The vulnerability allows for potential unauthorized access and data breaches. Affected systems may be vulnerable to explo [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-9201

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T19:17:48.657Z and has not been modified since then. The vulnerability is a cryptographic weakness in IBM Langflow OSS 1.0.0 through 1.10.3, allowing authenticated attackers to execute arbitrary code due to a weakness in the custom component validation mechanism. When the optional hardening mode i [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-9196

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to unintended code execution during Agentic Assistant validation due to improper handling of LLM-generated components. Authenticated attackers may execute code with backend privileges, potentially triggering side effects like outbound network access or data exfiltration. Users should assess their exposure, restrict execution privileges, and implement com [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-9130

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T19:17:46.797Z and has not been modified since then. IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The vulnerability affects multi-user deplo [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-8470

IBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable due to their use of Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. This practice, influenced by the deterministic nature of the Mersenne Twister PRNG, enables attackers to reproduce encryption keys and subsequently decrypt stored API keys and authentication tokens. The vulne [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-8183

IBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable to a directory traversal attack. An attacker could send a specially crafted URL request containing 'dot dot' sequences to view arbitrary files on the system. This vulnerability could allow a remote attacker to traverse directories on the system. Organizations should be aware of this vulnerability and take steps to mitigate it. Affected operator [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-7869

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem.

MEDIUM IBM CVE published 2026-08-05

CVE-2026-7658

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T19:17:43.580Z and has not been modified since then. IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected by a vulnerability allowing path traversal sequences. This could enable multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing k [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-17633

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to code injection, allowing a remote authenticated attacker to execute arbitrary code. The CVE record was published on 2026-08-05T19:17:29.043Z and has not been modified since then. This vulnerability has a CVSS score of 8.5 and is classified as HIGH severity. Affected users should prioritize patching to prevent potential attacks.

HIGH IBM CVE published 2026-08-05

CVE-2026-17632

IBM Langflow OSS 1.0.0 through 1.10.3 contains a vulnerability that could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning. This issue affects organizations using these versions, requiring prompt attention to mitigate potential code execution risks. The CVE record was published on 2026-08-05T19:17:28.923Z and has n [truncated]

MEDIUM IBM CVE published 2026-08-05

CVE-2026-10547

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T19:17:19.847Z and has not been modified since then. IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may [truncated]

HIGH IBM CVE published 2026-08-05

CVE-2026-9081

IBM Langflow OSS 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. This vulnerability allows an attacker to make unauthorized requests on behalf of the server, potentially leading to sensitive information disclosure or other malicious activities. Organizations using IBM Langflow OSS should be aware of thi [truncated]