CVE-2026-10545
Awaiting Analysis Awaiting Analysis - Queue

Open Redirect Vulnerability in IBM Planning Analytics Local

Vulnerability report for CVE-2026-10545, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: IBM Corporation

Description

IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm planning_analytics_local From 2.1.0 (inc) to 2.1.21 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Planning Analytics Local 2.1.0 through 2.1.21 has an open redirect vulnerability. Attackers can craft URLs that redirect users to malicious external sites. If used in single sign-on (SSO) flows, this could expose session tokens and allow attackers to hijack user sessions.

Detection Guidance

Detecting this vulnerability requires checking for open redirect flaws in IBM Planning Analytics Local. Review web server logs for unusual redirects to external domains. Inspect authentication flows for crafted URLs. Test with URLs containing redirect parameters like 'redirect_url' or 'return_url' pointing to external sites.

Impact Analysis

An attacker could trick you into clicking a malicious link, leading to session hijacking or theft of sensitive data. If you use SSO with this software, your session tokens may be exposed, allowing unauthorized access to your account.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements for data protection and access control. Organizations may face compliance violations and penalties if exploited.

Mitigation Strategies

Apply the latest IBM Planning Analytics Local patch to version 2.1.22 or later. Configure web server rules to block redirects to untrusted domains. Disable or restrict SSO authentication flows until patched. Monitor for suspicious redirect attempts in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10545. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart