CVE-2026-6935
HIGH
NVD
CVSS Score
7.8
Severity
HIGH
Published
Sep 23, 2026
Vendor
unknown
Description
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.