Improper RBAC Configuration in IBM Concert
IBM Concert versions 1.0.0 through 3.0.0 contain an access control vulnerability due to wildcard usage in RBAC permissions that allows authenticated attackers to access or modify unauthorized resources.
CVE search metadata
CVE search record: CVE-2026-17472. Severity: critical. CVSS: 9.6. KEV: no. Product: Concert (1.0.0 through 3.0.0). Brief: Improper RBAC Configuration in IBM Concert. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ibm-concert-rbac/
IBM Concert versions 1.0.0 through 3.0.0 are affected by an authorization bypass vulnerability identified as CVE-2026-17472. The issue stems from the implementation of wildcard characters within Role-Based Access Control (RBAC) permission definitions. This flaw permits a remote authenticated attacker to bypass intended authorization constraints, granting them the capability to access or modify resources outside the scope of their assigned privileges. Given the high CVSS score of 9.6, this vulnerability poses a significant risk of unauthorized data exposure or system manipulation for organizations utilizing affected versions of IBM Concert. Defenders should prioritize updating to a patched version to remediate the insecure permission logic.
Impact
Successful exploitation of this vulnerability allows an authenticated attacker to perform unauthorized operations, leading to potential data exfiltration, integrity loss, or administrative control over sensitive Concert resources. Impact is localized to the Concert application environment and its managed data.
Recommendation
Prioritize patching all instances of IBM Concert to the latest version provided by IBM that resolves the RBAC wildcard misconfiguration. Given the complexity of RBAC testing, review application logs for anomalous user access patterns or repeated unauthorized API calls originating from low-privileged accounts post-patching to ensure remediation is effective.
Immediate actions
Inventory all IBM Concert deployments and check current version
Mitigations
Upgrade IBM Concert to a non-vulnerable version when available
CVE-2026-17472