CVE-2026-13365: IBM Planning Analytics Local is affected by security vulnerabilities
IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Other sources
IBM Planning Analytics Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Planning Analytics Localto a version that resolves this vulnerability.Fixed in 2.1.23 - Compensating control
Since IBM Planning Analytics Local 2.1.0 through 2.1.22 is vulnerable to cross-site request forgery (CSRF), apply compensating network/web controls until upgrading—this material only specifies that IBM Planning Analytics Cloud has been remediated and that Local is vulnerable to CSRF.