Skip to content
Threat Feed
high advisory

Improper RBAC Configuration in IBM Concert

IBM Concert versions 1.0.0 through 3.0.0 contain an access control vulnerability due to wildcard usage in RBAC permissions that allows authenticated attackers to access or modify unauthorized resources.

CVE search metadata

CVE search record: CVE-2026-17472. Severity: critical. CVSS: 9.6. KEV: no. Product: Concert (1.0.0 through 3.0.0). Brief: Improper RBAC Configuration in IBM Concert. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ibm-concert-rbac/

IBM Concert versions 1.0.0 through 3.0.0 are affected by an authorization bypass vulnerability identified as CVE-2026-17472. The issue stems from the implementation of wildcard characters within Role-Based Access Control (RBAC) permission definitions. This flaw permits a remote authenticated attacker to bypass intended authorization constraints, granting them the capability to access or modify resources outside the scope of their assigned privileges. Given the high CVSS score of 9.6, this vulnerability poses a significant risk of unauthorized data exposure or system manipulation for organizations utilizing affected versions of IBM Concert. Defenders should prioritize updating to a patched version to remediate the insecure permission logic.

Impact

Successful exploitation of this vulnerability allows an authenticated attacker to perform unauthorized operations, leading to potential data exfiltration, integrity loss, or administrative control over sensitive Concert resources. Impact is localized to the Concert application environment and its managed data.

Recommendation

Prioritize patching all instances of IBM Concert to the latest version provided by IBM that resolves the RBAC wildcard misconfiguration. Given the complexity of RBAC testing, review application logs for anomalous user access patterns or repeated unauthorized API calls originating from low-privileged accounts post-patching to ensure remediation is effective.


Immediate actions

Inventory all IBM Concert deployments and check current version

IT Operations 24h

Mitigations

Upgrade IBM Concert to a non-vulnerable version when available

immediate IT Operations

CVE-2026-17472