CVE-2026-15322

Summary

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.

Affected Software

VendorProductVersion RangeStatus
IBMEngineering AI Hub1.0.0affected
IBMEngineering AI Hub1.1.0affected
IBMEngineering AI Hub1.2.0affected

Weaknesses

  • CWE-598: CWE-598 Use of HTTP Request With Sensitive Query String

References