Executive brief
IBM Engineering AI Hub is a platform used for managing AI-driven engineering lifecycles. A security flaw in versions 1.0.0 through 1.2.0 allows user session tokens to be exposed within web addresses (URLs). This could allow an unauthorized person to capture these tokens and gain access to sensitive engineering data or take over user accounts.
Technical details
IBM Engineering AI Hub is vulnerable to information disclosure (CWE-598) due to the use of the HTTP GET method for transmitting sensitive session tokens within query strings. Because these tokens are included in the URL, they may be logged by web servers, proxies, or browser history, or leaked via Referer headers. A remote, unauthenticated attacker who obtains these tokens can hijack active user sessions to access sensitive information. The vulnerability is resolved in IBM Engineering AI Hub version 1.3.0.
Affected products
- IBM Engineering AI Hub 1.0.0, 1.1.0, 1.2.0
Timeline
- 2026-07-17: advisory: IBM published the security bulletin and NVD record.
- 2026-07-17: patched: Vulnerability addressed in version 1.3.0.