← Vulnerability feed

Vulnerability record · CVE-2026-5065 · published 27 May 2026

CVE-2026-5065: Ibm controller hard-coded credentials vulnerability

Ibm · Controller

IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

8.8 CVSS 3.1 High EPSS 0.33% · top 76.1% CWE-798 · Hard-coded credentials
8.8CVSS 3.1 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-5065 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-28777Ibm cognos controller deserialization of untrusted data vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows us…EPSS 0.61%8.8CVE-2024-52902Ibm cognos controller hard-coded credentials vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code wh…EPSS 0.36%8.2CVE-2023-47160Ibm cognos controller xml external entity (xxe) vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when process…EPSS 0.52%8.2CVE-2024-40702Ibm cognos controller improper certificate validation vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to prote…EPSS 0.26%8.0CVE-2024-45084Ibm cognos controller csv injection vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An atta…EPSS 0.42%7.5CVE-2025-36326Ibm cognos controller vulnerabilityIBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to …EPSS 0.23%6.5CVE-2025-36015Ibm cognos controller vulnerabilityIBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of servi…EPSS 0.29%6.5CVE-2025-36017Ibm controller vulnerabilityIBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental va…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2026-5065), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.