EXPOSURES › CVE-2026-3627
CVE-2026-3627
CRITICALIBM Concert 1.0.0 through 2.3.1 suffers from a critical SQL injection flaw allowing remote attackers to read, modify, or delete database records.
A remote attacker can execute arbitrary SQL statements against IBM Concert, compromising data integrity and confidentiality. DIB organizations must patch this unpatched vulnerability immediately to prevent data exfiltration and unauthorized database manipulation, as it represents a severe avoidable failure in secure coding practices.
Shame score — A critical SQL injection vulnerability in a commercial product that remains unpatched and is actively exploitable demonstrates severe negligence and a failure to uphold basic secure development standards.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.