CVE-2026-15656CWE-614

CVE-2026-15656

Medium · published August 5, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
1.8
In the wild
Unconfirmed
What it is

IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00116 · 1.8th percentile
Weakness
CWE-614 · Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Published
2026-08-05T20:16Z
Affected products (3)
ProductVersionsFixed in
ibm/maximo_application_suite≥ 9.0, < 9.0.289.0.28
ibm/maximo_application_suite≥ 9.1, < 9.1.209.1.20
ibm/maximo_application_suiteall versions
References (1)
EPSS history
Timeline
  • 05 AUG 16:05Z
    IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret
    cvelistv5