CVE 7.2 HIGH

IBM Engineering Lifecycle Management – Jazz Foundation is vulnerable to Server Post-Auth Remote Code Execution_CVE-2026-4051

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

IBM Engineering Lifecycle Management 7.0.3 ( through ) Interim Fix 021, 7.1.0 ( through ) Interim Fix 009, and 7.2.0 ( through ) Interim Fix 001 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not properly restricted.

Basic Information

ID CVE-2026-4051
Source ibm
Published May 26, 2026 at 18:12

Affected Product

Vendor IBM
Product Engineering Lifecycle Management
Version 7.0.3
Affected Versions IBM Engineering Lifecycle Management 7.0.3
IBM Engineering Lifecycle Management 7.1.0
IBM Engineering Lifecycle Management 7.2.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.