Description
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs.
Published: 2026-07-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unsafe URL redirection flaw (CWE‑601) that allows a remote attacker to supply an unvalidated URL to IBM Engineering AI Hub, causing users to be redirected to malicious websites.

Affected Systems

IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 are affected. The flaw is resolved in the 1.0.01.3.0, 1.1.01.3.0, and 1.2.01.3.0 releases, with upgrade guidance provided by IBM.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score below 1% suggests a low likelihood of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. Attackers can exploit the flaw by presenting a crafted URL to a user, leading to an automatic redirection once the user interacts with the link.

Generated by OpenCVE AI on August 1, 2026 at 08:16 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected productFixed in releaseInstructionsIBM Engineering AI Hub v1.0.01.3.0 https://www.ibm.com/docs/en/engineering-ai-hub/1.3.0?topic=upgrading IBM Engineering AI Hub v1.1.01.3.0 https://www.ibm.com/docs/en/engineering-ai-hub/1.3.0?topic=upgrading IBM Engineering AI Hub v1.2.01.3.0 https://www.ibm.com/docs/en/engineering-ai-hub/1.3.0?topic=upgrading


OpenCVE Recommended Actions

  • Upgrade IBM Engineering AI Hub to the latest release (v1.0.01.3.0, v1.1.01.3.0, or v1.2.01.3.0) as directed by IBM.
  • If upgrading immediately is not possible, implement server‑side validation to ensure that only trusted URLs are used for redirects.
  • Configure application or network controls, such as a web application firewall, to detect and block unauthorized redirects while the system is pending a patch.

Generated by OpenCVE AI on August 1, 2026 at 08:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs.
Title Multiple Vulnerabilities in IBM Engineering AI hub.
First Time appeared Ibm
Ibm engineering Ai Hub
Weaknesses CWE-601
CPEs cpe:2.3:a:ibm:engineering_ai_hub:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_ai_hub:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:engineering_ai_hub:1.2.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm engineering Ai Hub
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Engineering Ai Hub
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-17T23:15:12.887Z

Reserved: 2026-07-08T16:10:36.076Z

Link: CVE-2026-15093

cve-icon Vulnrichment

Updated: 2026-07-17T20:05:19.088Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T08:30:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')