VYPR
Critical severity9.8NVD Advisory· Published May 26, 2026· Updated May 26, 2026

CVE-2026-3660

CVE-2026-3660

Description

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated remote attacker can modify server property files in IBM Engineering Lifecycle Management (Jazz Foundation) 7.0.3–7.2.0, leading to authentication bypass.

Vulnerability

IBM Engineering Lifecycle Management – Jazz Foundation versions 7.0.3 (through iFix021), 7.1.0 (through iFix009), and 7.2.0 (through iFix001) contain an incorrect authorization vulnerability (CWE-863) that allows an unauthenticated remote attacker to update server property files [1]. By modifying these configuration files, the attacker can bypass authentication controls and gain unauthorized access to the application.

Exploitation

An attacker can exploit this vulnerability over the network without any authentication or user interaction. The attack complexity is low because the vulnerable endpoint or mechanism that permits writing to server property files is exposed without proper access controls [1]. No special privileges or prior access are required.

Impact

Successful exploitation leads to authentication bypass, giving the attacker the ability to gain unauthorized access to the IBM Engineering Lifecycle Management application. The CVSS v3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a compromise of confidentiality, integrity, and availability at a high severity level [1].

Mitigation

IBM has released iFixes to address this vulnerability: iFix022 for version 7.0.3, iFix010 for version 7.1.0, and iFix002 for version 7.2.0 [1]. No workarounds are available [1]. Organizations should apply the appropriate iFix as soon as possible to prevent exploitation.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.