CVE-2026-16713
Awaiting Analysis Awaiting Analysis - Queue

IBM Documentation Offline Security Misconfiguration Exposes Sensitive Data

Vulnerability report for CVE-2026-16713, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: IBM Corporation

Description

IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation server binds to an unrestricted IP address.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm documentation From 1.0.0 (inc) to 1.4.1 (inc)
ibm documentation_offline From 1.0.0 (inc) to 1.4.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1327 The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Documentation Offline 1.0.0 through 1.4.1 has a security misconfiguration where the documentation server binds to all network interfaces instead of restricting access to the local loopback address. This allows remote attackers on the same network to access the server and potentially obtain sensitive information.

Detection Guidance

To detect this vulnerability, check if the IBM Documentation Offline server is binding to all network interfaces instead of the local loopback address. Use commands like netstat -tuln or ss -tuln to list listening ports and verify if the server is exposed to the network.

Impact Analysis

If you use IBM Documentation Offline versions 1.0.0 to 1.4.1, an attacker on your network could remotely access the documentation server and steal sensitive data. This could include internal documentation, configuration details, or other confidential information exposed by the server.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) or HIPAA (health information privacy). Unauthorized disclosure of such data could result in legal penalties or regulatory fines.

Mitigation Strategies

Immediately upgrade to IBM Documentation Offline version 1.5.1 or later, as this issue has been addressed in that release. If upgrading is not possible, restrict server access to the local loopback address (127.0.0.1) in the server configuration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16713. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart