CVE-2026-15322: Multiple Vulnerabilities in IBM Engineering AI hub.
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.
Other sources
IBM Engineering AI Hub could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering AI Hubto a version that resolves this vulnerability.Fixed in 1.3.0 - Configuration
Mitigate the issue by ensuring session tokens are not exposed in URLs (use a safer mechanism than embedding session tokens in query parameters/URL paths).
IBM Engineering AI Hub session tokens in URLs = not exposed in URLs