CVE-2026-6794: IBM Concert

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of the affected process.

Affected products

  • IBM Concert: from 1.0.0, up to and including 3.0.0

Published 2026-09-23. Last modified 2026-09-28.