SYS::ONLINE
Wasteland.
Briefs1899
Issues23
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2024-27253 2026-08-12

CVE-2024-27253: Critical Authentication Bypass in IBM DOORS Next

"IBM has disclosed a CVSS 10.0 authentication flaw in DOORS Next 7.0.3 that, per the vendor's own advisory language, could allow an authenticated user to bypass security logic and perform unauthorized activities."

IBM has disclosed a CVSS 10.0 authentication flaw in DOORS Next 7.0.3 that, per the vendor's own advisory language, could allow an authenticated user to bypass security logic and perform unauthorized activities.

What Is It

CVE-2024-27253 is an improper authentication weakness (CWE-287) in IBM DOORS Next, IBM's requirements management platform. According to IBM's PSIRT advisory, versions 7.0.3 through 7.0.3 Interim Fix 018 "could allow an authenticated user to bypass security logic to perform unauthorized activities."

The CVE was published on 2026-08-12 and currently carries an NVD status of "Received," meaning NVD analysis is still pending and details may be revised.

Why It Matters

IBM assigned this a CVSS 3.1 base score of 10.0 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. That breaks down to network-reachable, low attack complexity, no privileges required, no user interaction, and a changed scope; with high impact to confidentiality, integrity, and availability alike. The exploitability subscore is the maximum 3.9.

Note the tension in the supplied data: the vector states privileges required as NONE, while the description scopes the flaw to an authenticated user. That discrepancy is present in the vendor-supplied record and is not resolved by the source material.

DOORS Next typically holds requirements and design documentation for regulated engineering programs, so a security-logic bypass carries meaningful exposure for the data it governs.

What's Vulnerable

No other product lines or major versions are listed as affected in the supplied record.

Patch Status

IBM has published a support advisory for this issue (node 7282705). The affected range ends at Interim Fix 018, which indicates fixed code is delivered in a later interim fix; administrators should consult the IBM advisory directly for the exact remediation build and apply it.

No public exploit references are present in the source data reviewed here. That is an absence of evidence rather than a determination about exploitation: it does not establish that the flaw is unexploited in the wild, only that nothing in the reviewed sources records exploitation. Exploitation status was not assessed against any catalog of known exploited vulnerabilities, so readers who need that determination should consult those sources on their own.

Sources