CVE-2026-15322: Multiple Vulnerabilities in IBM Engineering AI hub.
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.
Other sources
IBM Engineering AI Hub could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering AI Hubto a version that resolves this vulnerability.Fixed in 1.3.0 - Configuration
Mitigate the issue by ensuring session tokens are not exposed in URLs (use a safer mechanism than embedding session tokens in query parameters/URL paths).
IBM Engineering AI Hub session tokens in URLs = not exposed in URLs
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15322?
The severity of CVE-2026-15322 is high, rated at 7.5 according to the CVSS scoring system.
How do I fix CVE-2026-15322?
To address CVE-2026-15322, ensure that session tokens are not exposed in URLs by implementing secure transmission practices.
What versions of IBM Engineering AI Hub are affected by CVE-2026-15322?
CVE-2026-15322 affects IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0.
What type of information can be exposed due to CVE-2026-15322?
CVE-2026-15322 can lead to the exposure of sensitive information as a result of session tokens being included in URLs.
Can CVE-2026-15322 be exploited remotely?
Yes, CVE-2026-15322 can be exploited remotely, allowing an attacker to obtain sensitive information.