A total of 5 severe vulnerabilities have been identified in IBM Documentation Offline, including one critical remote code execution flaw (CVE-2026-17482) with a CVSS score of 9.8. This vulnerability allows attackers to run malicious commands. Additional vulnerabilities include CVE-2026-17481 and CVE-2026-17473, rated high, while two others are medium severity. There are currently no confirmed exploits.
IBM urges users to upgrade to version 1.5.1, which addresses these vulnerabilities by removing hardcoded keys and securing file path controls. Restrictions on network access to the service interface are recommended for users unable to upgrade immediately.