CVE-2026-17482
Analyzed Analyzed - Analysis Complete

IBM Documentation Offline Remote Code Execution Vulnerability

Vulnerability report for CVE-2026-17482, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-17

Assigner: IBM Corporation

Description

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-17
Generated
2026-09-03
AI Q&A
2026-08-14
EPSS Evaluated
2026-09-01
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm documentation_offline From 1.0.0 (inc) to 1.5.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in IBM Documentation Offline versions 1.0.0 through 1.4.1 allows a remote attacker to execute arbitrary code by exploiting improper control of file paths. This means an attacker could manipulate file paths to run malicious code on a victim's system.

Detection Guidance

This vulnerability involves improper file path control in IBM Documentation Offline 1.0.0 through 1.4.1, allowing remote code execution. To detect it, check installed versions of IBM Documentation Offline and inspect file path handling in application logs or configurations. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow an attacker to take control of your system, steal data, install malware, or perform other malicious actions. Since it affects remote execution, any user running the vulnerable software could be at risk.

Compliance Impact

This vulnerability allows remote attackers to execute arbitrary code due to improper file path control. This could lead to unauthorized access, data breaches, or system compromise, which may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data security) by exposing sensitive information or failing to ensure data integrity and confidentiality.

Mitigation Strategies

Update IBM Documentation Offline to a version beyond 1.4.1 to address the arbitrary code execution risk due to improper file path control.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17482. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart