EIP-2026-103939

PRE-CVE

IBM Net.Commerce 3.1/3.2 Websphere - Weak Password

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103939. PoCs published by Rudi Carell.

AI-analyzed exploit summary The exploit describes a weak password encryption vulnerability in IBM NetCommerce and WebSphere Commerce Suite, which can be decrypted using a publicly available tool. Compromise of user or administrator accounts could lead to sensitive information disclosure or further system compromises.

Description

IBM Net.Commerce 3.1/3.2 Websphere - Weak Password

Exploits (1)

exploitdb WRITEUP VERIFIED
by Rudi Carell · textremotemultiple
https://www.exploit-db.com/exploits/20685

The exploit describes a weak password encryption vulnerability in IBM NetCommerce and WebSphere Commerce Suite, which can be decrypted using a publicly available tool. Compromise of user or administrator accounts could lead to sensitive information disclosure or further system compromises.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: IBM NetCommerce, WebSphere Commerce Suite
No auth needed
Prerequisites: Access to encrypted password storage · Publicly available decryption tool
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026