Junglewise Threat Intelligence

CVE-2026-10545: IBM Planning Analytics Local open redirect in Workspace

CVE-2026-10545 · Severity: high · CVSS 7.5 · Published 2026-07-30

Executive brief

IBM Planning Analytics Local, a business performance management platform, is vulnerable to an open redirect flaw. An attacker can trick users into clicking a malicious link that appears to be a legitimate IBM URL but instead redirects them to a fraudulent website. If this occurs during a single sign-on (SSO) login process, the attacker could steal the user's session tokens and gain unauthorized access to their account and corporate data.

Technical details

IBM Planning Analytics Local versions 2.1.0 through 2.1.21 contain an open redirect vulnerability (CWE-601). The flaw exists because the application fails to properly validate destination URLs provided in request parameters. An unauthenticated remote attacker can exploit this by crafting a URL that redirects a victim to an external, attacker-controlled domain. If the redirect occurs during an SSO authentication flow, sensitive session tokens may be appended to the URL or included in headers sent to the malicious site, allowing for session hijacking. The vulnerability is addressed in IBM Planning Analytics Workspace version 2.1.22.

Affected products

  • IBM Planning Analytics Local 2.1.0 through 2.1.21

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References