CVE-2026-1267
Received
Received - Intake
Unauthorized Access in IBM Planning Analytics Local via Access Control Flaw
Publication date: 2026-03-17
Last updated on: 2026-03-19
Assigner: IBM Corporation
Description
Description
IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and administrative functionalities due to lack of proper access controls.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | planning_analytics_local | From 2.1.0 (inc) to 2.1.18 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |