CVE-2026-15091: IBM Engineering Ai Hub

Critical severity, CVSS 9.3. EPSS: 0.6% chance of exploitation in the next 30 days.

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation.

Affected products

  • IBM Engineering Ai Hub: from 1.0.0, before 1.3.0 (fixed in 1.3.0)

Published 2026-07-17. Last modified 2026-07-24.