Multiple security vulnerabilities affecting IBM Documentation Offline versions. These security defects affect IBM Documentation Offline versions 1.0.0 through 1.4.1 and pose a severe risk to corporate environments, allowing attackers to gain unauthorized access to sensitive workstations and compromise the confidentiality, integrity, and availability of the host system.
CVE-2026-17482 (CVSS 9.8 — Critical): A critical IBM remote code execution flaw allows attackers to run malicious commands directly due to improper control of file paths and unsanitized external input supplied to the server’s template engine.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting IBM Documentation Offline versions. These security defects affect IBM Documentation Offline versions 1.0.0 through 1.4.1 and pose a severe risk to corporate environments, allowing attackers to gain unauthorized access to sensitive workstations and compromise the confidentiality, integrity, and availability of the host system.
CVE-2026-17482 (CVSS 9.8 — Critical): A critical IBM remote code execution flaw allows attackers to run malicious commands directly due to improper control of file paths and unsanitized external input supplied to the server’s template engine.[emaillocker id="1283"]
CVE-2026-17481 (CVSS 8.8 — High): This vulnerability triggers through improper neutralization of log output, enabling attackers to forge valid session tokens.
CVE-2026-17473 (CVSS 7.5 — High): The embedded Node.js web server uses a hardcoded session secret, allowing attackers to forge valid session tokens.
CVE-2026-17468 (CVSS 5.3 — Medium): This vulnerability occurs due to insecure binding of network sockets to all available network interfaces.
CVE-2026-16713 (CVSS 4.3 — Medium): The embedded Node.js web server fails to properly sanitize external input supplied to the server’s template engine, enabling attackers to run malicious commands directly.
These vulnerabilities collectively present a severe risk to corporate environments.
We recommend you to update IBM Documentation Offline to version 1.5.1.
The following reports contain further technical details:
[/emaillocker]