CVE-2026-14350CWE-117

CVE-2026-14350

Medium · published September 4, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
23.4
In the wild
Unconfirmed
What it is

IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00310 · 23.4th percentile
Weakness
CWE-117 · Improper Output Neutralization for Logs
Published
2026-09-04T21:16Z
References (1)
EPSS history
Timeline
  • 06 SEP 03:29Z
    EPSS moved — → 0%
    epss
  • 04 SEP 16:44Z
    Vulnerabilities exists in IBM Cloud Pak for Data System
    cvelistv5