CVE-2026-17482

9.8

IBM · Documentation Offline

IBM Documentation Offline 1.0.0 through 1.4.1 contains a path traversal vulnerability that permits unauthenticated remote attackers to execute arbitrary code.

Executive summary

A critical path traversal vulnerability in IBM Documentation Offline allows unauthenticated remote attackers to achieve arbitrary code execution on affected systems.

Vulnerability

This vulnerability is caused by improper control of file paths (CWE-73), which allows an unauthenticated attacker to manipulate file operations. By injecting malicious path sequences, a remote actor can execute arbitrary code within the context of the application.

Business impact

The severity is rated at 9.8 (Critical) because the vulnerability allows for unauthenticated remote code execution. Successful exploitation could lead to a complete system compromise, unauthorized data access, and significant service disruption, posing a severe risk to organizational operations and data integrity.

Remediation

Immediate Action: Update IBM Documentation Offline to version 1.5.1 or later immediately, as recommended by the vendor.

Proactive Monitoring: Monitor server access logs for unusual path traversal patterns or unauthorized requests directed at system files.

Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to block suspicious directory traversal sequences and requests targeting sensitive system paths.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Given the critical nature of this vulnerability and the potential for full system compromise, administrators should prioritize the update to version 1.5.1. Immediate application of this patch is the only reliable way to eliminate the risk of remote code execution.

More IBM CVEs