Junglewise Threat Intelligence

CVE-2026-15069: IBM Engineering AI Hub OS command injection

CVE-2026-15069 · Severity: medium · CVSS 5.4 · Published 2026-07-17

Technologies: IBM Engineering AI Hub. Vendors: IBM.

Executive brief

IBM Engineering AI Hub is a platform used for managing AI-driven engineering lifecycles. A security vulnerability in this product could allow a remote attacker to execute unauthorized scripts or commands by tricking a user into interacting with a malicious link or page. This could lead to unauthorized actions being performed on behalf of the user or limited access to sensitive system information.

Technical details

This vulnerability is classified as OS Command Injection (CWE-78) resulting from improper neutralization of special elements during web page generation. A remote, unauthenticated attacker can exploit this by sending a specially crafted request, though successful exploitation requires some level of user interaction (UI:R). If successful, the attacker could execute arbitrary script code or OS commands within the context of the application. The issue affects IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0, and has been addressed in version 1.3.0.

Affected products

  • IBM Engineering AI Hub 1.0.0, 1.1.0, 1.2.0

Timeline

  • 2026-07-17: advisory: Initial advisory published by IBM and NVD.
  • 2026-07-17: patched: Vulnerability addressed in version 1.3.0.

References

Related threats