IBM disclosed CVE-2026-17482, a CVSS 9.8 flaw in IBM Documentation Offline that lets an unauthenticated remote attacker execute arbitrary code through improper control of file paths.
What Is It
CVE-2026-17482 is an external control of file name or path issue (CWE-73) in IBM Documentation Offline. According to IBM's PSIRT advisory, the product "could allow a remote attacker to execute arbitrary code due to improper control of file paths."
The CVSS 3.1 base score is 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That breaks down to network-reachable attack surface, low attack complexity, no privileges required, and no user interaction; with high impact to confidentiality, integrity, and availability. The exploitability subscore is a maximum 3.9.
Why It Matters
Remote code execution with no authentication and no user interaction is the shortest possible path from external access to full control of the affected host. Because the flaw stems from attacker influence over file paths, exploitation likely requires nothing more than a crafted request to a reachable instance.
CVE-2026-17482 does not appear in CISA's Known Exploited Vulnerabilities catalog, which is published publicly and can be checked directly at the link in Sources below. That means CISA has not confirmed active exploitation as of this writing; a status that can change, so defenders should re-check the catalog rather than treat its absence as durable. The lack of a KEV listing does not lower the technical severity; it only means CISA has not documented in-the-wild use.
What's Vulnerable
- Vendor: IBM
- Product: Documentation Offline
- Affected versions: 1.0.0 through 1.4.1 (inclusive)
Listed CPEs cover cpe:2.3:a:ibm:documentation_offline:1.0.0 and cpe:2.3:a:ibm:documentation_offline:1.4.1, with the version range flagged as affected from 1.0.0 up to and including 1.4.1.
Patch Status
The CVE record was published 2026-08-13 with a status of "Received," meaning NVD enrichment is still pending. The record specifies no fixed version number and no required-action deadline.
The only vendor reference in the record is IBM Support node 7283484. Administrators running IBM Documentation Offline in the 1.0.0–1.4.1 range should consult that advisory directly for remediation guidance and confirm whether a fixed release is available.
Sources
- IBM Support Advisory; https://www.ibm.com/support/pages/node/7283484
- NVD, CVE-2026-17482, https://nvd.nist.gov/vuln/detail/CVE-2026-17482
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog