CVE-2026-5935 is a command injection vulnerability affecting IBM Total Storage Service Console (TSSC) and TS4500 Intelligent Management Console (IMC) versions 9.2 through 9.6. The flaw stems from improper validation of user-supplied input, allowing unauthenticated attackers to execute arbitrary commands with standard user privileges on affected systems. The vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, meaning exploitation is straightforward for threat actors. Potential impacts include confidentiality loss, integrity compromise, and availability disruption, though the damage is limited to normal user-level privileges rather than administrative access. This vulnerability is currently listed on the CISA Known Exploited Vulnerabilities (KEV) Catalog and appears on the Active Hot List, indicating active exploitation in the wild. However, the extremely low EPSS score of 0.00047 suggests minimal prevalence in real-world exploitation attempts relative to other disclosed vulnerabilities. Organizations running TSSC or IMC within the affected version range should prioritize patching given the demonstrated active exploitation risk despite low statistical exploitation probability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.2CPE matchmatch criteria | cpe:2.3:a:ibm:total_storage_service_console:9.2:*:*:*:*:*:*:* | ||
9.3CPE matchmatch criteria | cpe:2.3:a:ibm:total_storage_service_console:9.3:*:*:*:*:*:*:* | ||
9.4CPE matchmatch criteria | cpe:2.3:a:ibm:total_storage_service_console:9.4:*:*:*:*:*:*:* | ||
9.5CPE matchmatch criteria | cpe:2.3:a:ibm:total_storage_service_console:9.5:*:*:*:*:*:*:* | ||
9.6CPE matchmatch criteria | cpe:2.3:a:ibm:total_storage_service_console:9.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.