CVE-2026-12628 Details
Description
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentication code paths, and does not properly validate authentication responses, which may allow an unauthenticated attacker to establish a trusted session and access protected services. This vulnerability affects client components across multiple versions and may allow an attacker to impersonate legitimate clients, potentially leading to unauthorized access to system resources.
A vulnerability exists in IBM Storage Protect Client versions 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows versions 8.1.0.0 through 8.2.1.0. The issue arises from a hardcoded credential in the FlashCopy Manager authentication process, which is embedded in multiple code paths. This static credential is not properly validated, potentially allowing an unauthenticated remote attacker to bypass authentication, establish a trusted session, and access protected services. As a result, there is a risk of unauthorized access to system resources by impersonating legitimate clients.
Users of IBM Storage Protect Snapshot For Windows should upgrade to version 8.2.1.1, which addresses the vulnerability by removing the hardcoded credential. For IBM Storage Protect Client, the vulnerability has been identified but not yet addressed; however, it is not actively used and is only detected during static code scans.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7277245 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm storage protect | >= 8.1.0.0, < 8.2.1.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | CVE Modified | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | New CVE Received | [email protected] |