CVE-2026-15656: IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret

Published Aug 3, 2026
·
Updated

IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

Other sources

IBM Maximo Application Suite does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

IBM

Affected Software

7 affected components
IBM Maximo Application Suite>=9.0<=9.2
IBM Maximo Application Suite<=9.2
IBM Maximo Application Suite<=9.1
IBM Maximo Application Suite<=9.0
IBM Maximo Application Suite>=9.0<9.0.28
IBM Maximo Application Suite>=9.1<9.1.20
IBM Maximo Application Suite=9.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade IBM Maximo Application Suite to a version that resolves this vulnerability.

    Fixed in 9.2.1
  2. Upgrade

    Upgrade IBM Maximo Application Suite to a version that resolves this vulnerability.

    Fixed in 9.1.20
  3. Upgrade

    Upgrade IBM Maximo Application Suite to a version that resolves this vulnerability.

    Fixed in 9.0.28
  4. Configuration

    Ensure IBM MAS sets the Secure attribute on the mas-redirect-uri cookie and on authorization tokens and session cookies (so cookies are not sent over insecure HTTP links).

    IBM Maximo Application Suite (mas-redirect-uri cookie / authorization tokens / session cookies) Secure attribute = enabled
  5. Compensating control

    Prevent users from following insecure HTTP links to IBM MAS by blocking HTTP access and enforcing HTTPS for the relevant MAS endpoints.

Event History

Aug 3, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Aug 5, 2026
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-15656?

The severity of CVE-2026-15656 is rated as medium with a score of 4.3.

2

How do I fix CVE-2026-15656?

To fix CVE-2026-15656, ensure that the secure attribute is set on all authorization tokens and session cookies in IBM Maximo Application Suite.

3

What vulnerabilities are associated with CVE-2026-15656?

CVE-2026-15656 is linked to vulnerabilities such as missing secure attributes on cookies and weak HMAC session secrets.

4

What software is affected by CVE-2026-15656?

CVE-2026-15656 affects IBM Maximo Application Suite versions 9.2, 9.1, and 9.0.

5

How can attackers exploit CVE-2026-15656?

Attackers can exploit CVE-2026-15656 by sending a user an insecure link that captures authorization tokens or session cookie values.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203