Vulnary
← back to the feed
Critical· 9.3

CVE-2026-15091

IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 contain a cross-site scripting vulnerability that allows a remote attacker to inject and execute arbitrary scripts in a user's browser. The issue arises from improper neutralization of input during web page generation. No known exploitation or public exploit is currently reported.

publishedJul 17, 2026
last modifiedJul 24, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
25th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0

02

Real-world impact

An attacker could run malicious scripts in the context of a victim's browser, potentially stealing data or performing actions on behalf of the user.

03

Why this severity

CVSS v3.1 base score 9.3 (Critical) due to network‑adjacent attack vector, low complexity, no privileges required, user interaction needed, and high confidentiality and integrity impacts.

04

What to do about it

no official fix yet
recommended steps
  1. 01No official fix is mentioned in the provided sources; monitor the vendor’s security advisories for future patches.
interim mitigations
  • Apply input validation and output encoding to neutralize user‑supplied data before it is included in web pages.
  • Consider using Content Security Policy (CSP) headers to reduce the impact of successful XSS attempts.

Remediation guidance is based on general best practices for CWE‑79; no vendor‑specific patch is referenced in the supplied data.

05

Timeline

  1. Jul 17, 2026 · 16d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 24, 2026 · 9d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionRequired
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactNone
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →