CVE-2026-16426
Last modified
CVE-2026-16426 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| IBM | Concert | >= 1.0.0, <= 3.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-16426?
How severe is CVE-2026-16426?
How do I fix CVE-2026-16426?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1642A vulnerability exists in NGINX OSS and NGINX Plus when conf…8.2
- CVE-2026-16420Type Confusion in WebAudio in Google Chrome prior to 150.0.7…8.8
- CVE-2026-16421Inappropriate implementation in WebAudio in Google Chrome pr…8.8
- CVE-2026-16422Insufficient validation of untrusted input in Certificate in…7.5
- CVE-2026-16423Use after free in UI in Google Chrome prior to 150.0.7871.18…8.8
- CVE-2026-16424Use after free in GPU in Google Chrome on Android prior to 1…9.6
- CVE-2026-16428IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage co…8.8
- CVE-2026-1643The MP-Ukagaka plugin for WordPress is vulnerable to Reflect…6.1
- CVE-2026-16432IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage Px…7.7
- CVE-2026-16434Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an inc…2.3
- CVE-2026-16435IBM WebSphere Application Server 9.0, and 8.5 is affected by…5.9
- CVE-2026-16439In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trac…9.1
Are you affected by CVE-2026-16426?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
