CVE-2026-8862
nicheHardcoded credentials in IBM Netezza 11.3 expose private container registry images
IBM Netezza Software 11.3.0.3 through Interim Fix 002 contains hardcoded credentials in the application source code (CWE-522, insufficiently protected credentials), which allow unauthorized access to the product's container registry. Because the secret is embedded in the code and requires no privileges or user interaction to use (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), an attacker with network access can authenticate to the registry using the embedded credential. Successful abuse lets the attacker pull private container images, potentially exposing proprietary code, configuration details, and other sensitive information. Anyone running an affected IBM Netezza Software release in the 11.3.0.3 through Interim Fix 002 range is in scope. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.2%, so no exploitation is currently known.
What to do: Upgrade Netezza Software to a fixed release/interim fix newer than 11.3.0.3 IF002 per IBM's advisory. Until patched, restrict network access to the container registry, treat the embedded registry credential as compromised by rotating it, and review registry access logs for unauthorized pulls of private images.
| IBM Netezza Software | 11.3.0.3 through Interim Fix 002 (IF002) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information.
- Vendors
- ibm
- Products
- netezza performance server
- Weakness
- CWE-522
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.