CVE-2025-14806: IBM Planning Analytics Local

Medium severity, CVSS 5.7. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources.

Affected products

  • IBM Planning Analytics Local: from 2.1.0, before 2.1.18 (fixed in 2.1.18)

Published 2026-03-17. Last modified 2026-06-17.