Improper Handling of Windows Device Names in Werkzeug - CVE-2026-21860
Published: March 5, 2026
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, AUX, etc that are implicitly present and readable in every directory. Windows still accepts them with any file extension, such as CON.txt, or trailing spaces such as CON. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
IBM Cloud Pak for Data System
IBM Maximo Application Suite
watsonx Code Assistant On Prem
Maximo Application Suite - Predict Component
Maximo Application Suite - Location Service for Esri Component
Maximo Application Suite Ai Service
Storage Protect Plus Server
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2026-21860
IBM Cloud Pak for Data System - update to 1.0.10.0
watsonx Code Assistant On Prem - update to 5.3.1
Maximo Application Suite - Predict Component - addressed in versions 8.8.14, 8.9.16, 9.0.13, 9.1.6
IBM Maximo Application Suite - addressed in versions 8.10.36, 8.11.33, 9.0.22, 9.1.11
Maximo Application Suite - Location Service for Esri Component - addressed in versions 9.0.7, 9.1.6
Maximo Application Suite Ai Service - update to 9.1.13
Storage Protect Plus Server - update to 10.1.18
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2
External References
Related Security Bulletins
- Improper Handling of Windows Device Names in Werkzeug
- Multiple vulnerabilities in IBM watsonx Code Assistant On Prem
- Multiple vulnerabilities in IBM Maximo Application Suite - Location Service for Esri Component
- IBM Maximo Application Suite - Predict Component update for Werkzeug
- Multiple vulnerabilities in IBM Maximo AI Service
- IBM Cloud Pak for Data System 2.0 update for Werkzeug
- Multiple vulnerabilities in IBM Storage Protect Plus Server
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak