Junglewise Threat Intelligence

CVE-2026-7365: IBM Operations Analytics use of default credentials in Log Analysis

CVE-2026-7365 · Severity: high · CVSS 8.4 · Published 2026-05-27

Executive brief

IBM Operations Analytics and SmartCloud Analytics, tools used for monitoring and analyzing IT log data, contain a security flaw where default passwords are not forced to be changed after installation. This could allow an unauthorized person with local access to the system to bypass authentication and gain full control over the application. Such an exploit could lead to the exposure of sensitive log data or disruption of monitoring services.

Technical details

The vulnerability (CWE-1392) exists because the installation process for IBM Operations Analytics - Log Analysis and SmartCloud Analytics - Log Analysis sets default credentials that remain active unless manually changed by an administrator. An attacker with local access can use these known default passwords to bypass the authentication mechanism of the Log Analysis User Interface. Successful exploitation grants the attacker high-level access (High Confidentiality, Integrity, and Availability impact). IBM recommends that administrators manually reset the password through the GUI or integrate the product with LDAP to mitigate this risk. For versions prior to 1.3.7.0, an upgrade to 1.3.7-TIV-IOALA-FP_signed or later is required before applying the fix.

Affected products

  • IBM Operations Analytics - Log Analysis 1.3.2.0, 1.3.3.0, 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.6.2, 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4
  • IBM SmartCloud Analytics - Log Analysis 1.3.2.0, 1.3.3.0, 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.6.2, 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4

Timeline

  • 2026-05-07: disclosed: Initial publication of the IBM security bulletin.
  • 2026-05-27: advisory: NVD published the CVE record.

References

Related threats