Description
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during web page generation.
Published: 2026-07-17
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 contain an input sanitization flaw that allows a remote attacker to execute arbitrary script code during web page generation. This flaw is an instance of CWE‑78 (OS Command Injection) and enables the attacker to run unintended commands on the host system, compromising confidentiality, integrity, and availability of the affected application.

Affected Systems

The vulnerability impacts IBM Engineering AI Hub from versions 1.0.0 through 1.2.0. Users running any of these released versions should verify that they are not operating the vulnerable build.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw can be triggered remotely via crafted input delivered to the web page generator. Unlike publicly disclosed exploits, it is not currently listed in the CISA KEV catalog, which implies that no mass‑mode exploitation has been confirmed yet.

Generated by OpenCVE AI on July 30, 2026 at 23:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected productFixed in releaseInstructionsIBM Engineering AI Hub v1.0.01.3.0 https://www.ibm.com/docs/en/engineering-ai-hub/1.3.0?topic=upgrading IBM Engineering AI Hub v1.1.01.3.0 https://www.ibm.com/docs/en/engineering-ai-hub/1.3.0?topic=upgrading IBM Engineering AI Hub v1.2.01.3.0 https://www.ibm.com/docs/en/engineering-ai-hub/1.3.0?topic=upgrading


OpenCVE Recommended Actions

  • Upgrade IBM Engineering AI Hub to a fixed release, such as v1.0.01.3.0 or newer, following IBM’s upgrade guidance.
  • If an immediate upgrade is not feasible, implement input restrictions or sanitization for data used in web page generation to ensure that no unsanitized values are passed to system commands.
  • Continuously monitor application logs for signs of unexpected command execution or other anomalous activity, and apply additional logging or alerting around the web generation component if possible.

Generated by OpenCVE AI on July 30, 2026 at 23:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during web page generation.
Title Multiple Vulnerabilities in IBM Engineering AI hub.
First Time appeared Ibm
Ibm engineering Ai Hub
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:engineering_ai_hub:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_ai_hub:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_ai_hub:1.2.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm engineering Ai Hub
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Engineering Ai Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-20T13:52:29.108Z

Reserved: 2026-07-08T14:46:51.365Z

Link: CVE-2026-15069

cve-icon Vulnrichment

Updated: 2026-07-20T13:52:25.308Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:45:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')