Session Token Forgery Vulnerability in IBM Documentation Offline
CVE-2026-17468
5.3MEDIUM
What is CVE-2026-17468?
The IBM Documentation Offline product versions 1.0.0 through 1.4.1 are susceptible to a vulnerability that allows a remote attacker to forge valid session tokens. This risk is attributed to the use of a hardcoded cryptographic key, which could lead to unauthorized access and potential data compromise. Users are encouraged to review the advisory provided by IBM and apply the necessary patches to mitigate this security issue.
Affected Version(s)
Documentation Offline 1.0.0 <= 1.4.1