QSearchQSearch

CVE-2026-4051

7.2 HIGH

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote cod...

Published: 2026-05-26 · Last updated: 2026-05-27

Severity and scoring

CVSS
7.2 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-749

Affected products

VendorProduct
ibmengineering_lifecycle_management

Description

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-4870 IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of service due to uncontr... (7.5 HIGH)
  • CVE-2026-7870 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call (8.8 HIGH)
  • CVE-2026-4096 IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers (6.5 MEDIUM)
  • CVE-2024-45636 IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user (4.1 MEDIUM)
  • CVE-2026-9330 IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using th... (8.5 HIGH)

Same CWE

  • CVE-2026-49993 Nuxt is an open-source web development framework for Vue.js (5.7 MEDIUM)
  • CVE-2026-45670 Nuxt is an open-source web development framework for Vue.js (5.4 MEDIUM)
  • CVE-2026-12060 Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attacker... (6.5 MEDIUM)
  • CVE-2026-7516 A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could al... (4.3 MEDIUM)
  • CVE-2026-47899 The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers without proper path v...