CVE Vulnerabilities

CVE-2026-15322

Use of HTTP Request With Sensitive Query String

Published: Jul 17, 2026 | Modified: Jul 24, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs.

Weakness

The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.

Affected Software

NameVendorStart VersionEnd Version
Engineering_ai_hubIbm1.0.0 (including)1.3.0 (excluding)

Potential Mitigations

References