CVE-2026-5065
Analyzed Analyzed - Analysis Complete
Hard-Coded Credentials in IBM Controller

Publication date: 2026-05-27

Last updated on: 2026-06-02

Assigner: IBM Corporation

Description
IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-27
Last Modified
2026-06-02
Generated
2026-06-16
AI Q&A
2026-05-27
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
ibm controller From 11.0.1 (inc) to 11.1.3 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability in IBM Controller versions 11.0.1, 11.1.0, 11.1.1, and 11.1.2 involves the presence of hard-coded credentials such as passwords or cryptographic keys. These credentials are used internally for inbound authentication, outbound communication to external components, or encryption of internal data.

Impact Analysis

This vulnerability can have a severe impact because hard-coded credentials can be extracted and misused by attackers to gain unauthorized access to the system. This can lead to unauthorized data access, remote code execution, and compromise of confidentiality, integrity, and availability of the affected system.

Mitigation Strategies

IBM recommends upgrading to IBM Controller version 11.1.3 to address the vulnerabilities, including the hard-coded credentials issue.

No workarounds are provided, so applying the update promptly is critical due to the evolving exploit potential.

Compliance Impact

The vulnerability involves hard-coded credentials in IBM Controller versions 11.0.1 through 11.1.2, which can lead to unauthorized access, data exposure, and compromise of confidentiality, integrity, and availability. Such security weaknesses can negatively impact compliance with common standards and regulations like GDPR and HIPAA, which require strong access controls and protection of sensitive data.

However, the provided information does not explicitly mention the impact on compliance with specific regulations or standards.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5065. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart