CVE-2026-15093: Multiple Vulnerabilities in IBM Engineering AI hub.
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs.
Other sources
IBM Engineering AI Hub could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering AI Hubto a version that resolves this vulnerability.Fixed in 1.3.0 - Compensating control
Temporarily restrict access to the IBM Engineering AI Hub instance until upgrading to 1.3.0 is completed to reduce exposure to URL redirect attacks.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15093?
The severity of CVE-2026-15093 is classified as medium with a score of 4.3.
How do I fix CVE-2026-15093?
To fix CVE-2026-15093, update to a patched version of IBM Engineering AI Hub that addresses the URL validation vulnerabilities.
What vulnerabilities are associated with CVE-2026-15093?
CVE-2026-15093 involves multiple vulnerabilities that allow remote attackers to redirect users due to improper validation of user-supplied URLs.
What versions of IBM Engineering AI Hub are affected by CVE-2026-15093?
IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 are affected by CVE-2026-15093.
What are the potential impacts of CVE-2026-15093?
The potential impact of CVE-2026-15093 includes the risk of users being redirected to malicious websites.