CVE-2026-18531: IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.
Other sources
IBM Maximo Application Suite could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Maximo Application Suiteto a version that resolves this vulnerability.Fixed in 9.2.1 - Upgrade
Upgrade
IBM Maximo Application Suiteto a version that resolves this vulnerability.Fixed in 9.1.20 - Upgrade
Upgrade
IBM Maximo Application Suiteto a version that resolves this vulnerability.Fixed in 9.0.28
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18531?
The severity of CVE-2026-18531 is rated as medium with a score of 5.3.
How do I fix CVE-2026-18531?
To fix CVE-2026-18531, update IBM Maximo Application Suite to the latest version that addresses the vulnerabilities.
What vulnerabilities are associated with CVE-2026-18531?
CVE-2026-18531 is associated with vulnerabilities related to a weak HMAC session signing secret and missing Secure attribute on the mas-redirect-uri cookie.
What versions of IBM Maximo Application Suite are affected by CVE-2026-18531?
CVE-2026-18531 affects IBM Maximo Application Suite versions 9.0, 9.1, and 9.2.
Could CVE-2026-18531 allow an attacker to compromise session data?
Yes, CVE-2026-18531 could allow a remote attacker to tamper with session data due to a weak HMAC session signing secret.