CVE-2026-15091: Multiple Vulnerabilities in IBM Engineering AI hub.
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
Other sources
IBM Engineering AI Hub could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering AI Hubto a version that resolves this vulnerability.Fixed in 1.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15091?
CVE-2026-15091 has a critical severity rating of 9.3.
How can I mitigate CVE-2026-15091?
To mitigate CVE-2026-15091, update IBM Engineering AI Hub to the latest version released after the vulnerability was identified.
What types of attacks does CVE-2026-15091 allow?
CVE-2026-15091 allows for remote attackers to execute arbitrary scripts on affected systems.
Which versions of IBM Engineering AI Hub are affected by CVE-2026-15091?
IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 are affected by CVE-2026-15091.
What kind of vulnerability is CVE-2026-15091 classified as?
CVE-2026-15091 is classified as a Cross-Site Scripting (XSS) vulnerability.