Skip to content
COOEY

EXPOSURES › CVE-2026-3627

CVE-2026-3627

CRITICAL
DETAIL
SourceNVD · cve Published2026-08-28 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-3627 ↗
SHAME 78/100 unpatcheddata-breach

IBM Concert 1.0.0 through 2.3.1 suffers from a critical SQL injection flaw allowing remote attackers to read, modify, or delete database records.

A remote attacker can execute arbitrary SQL statements against IBM Concert, compromising data integrity and confidentiality. DIB organizations must patch this unpatched vulnerability immediately to prevent data exfiltration and unauthorized database manipulation, as it represents a severe avoidable failure in secure coding practices.

Shame score — A critical SQL injection vulnerability in a commercial product that remains unpatched and is actively exploitable demonstrates severe negligence and a failure to uphold basic secure development standards.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.