LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-12628

ibm · storage protect

Published
CVSS9.1
Severitycritical
WeaknessCWE-798
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentication code paths, and does not properly validate authentication responses, which may allow an unauthenticated attacker to establish a trusted session and access protected services. This vulnerability affects client components across multiple versions and may allow an attacker to impersonate legitimate clients, potentially leading to unauthorized acce

References

← Back to the CVE Tracker

Our coverage of CVE-2026-12628

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-12628.