CVE-2026-13365: IBM Planning Analytics Local is affected by security vulnerabilities
IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Other sources
IBM Planning Analytics Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Planning Analytics Localto a version that resolves this vulnerability.Fixed in 2.1.23 - Compensating control
Since IBM Planning Analytics Local 2.1.0 through 2.1.22 is vulnerable to cross-site request forgery (CSRF), apply compensating network/web controls until upgrading—this material only specifies that IBM Planning Analytics Cloud has been remediated and that Local is vulnerable to CSRF.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13365?
The severity of CVE-2026-13365 is rated as high with a score of 7.1.
How do I fix CVE-2026-13365?
To fix CVE-2026-13365, update IBM Planning Analytics to the latest version that addresses the cross-site request forgery vulnerability.
What types of attacks does CVE-2026-13365 expose users to?
CVE-2026-13365 exposes users to cross-site request forgery attacks that can lead to unauthorized actions being executed.
Which versions of IBM Planning Analytics are affected by CVE-2026-13365?
CVE-2026-13365 affects IBM Planning Analytics versions 2.0 and 2.1 Local.
What is the impact of CVE-2026-13365 on IBM Planning Analytics?
The impact of CVE-2026-13365 allows attackers to perform malicious actions on behalf of trusted users, compromising security.