What is CVE-2026-10545?
IBM Planning Analytics Local (versions 2.1.0 through 2.1.21) is vulnerable to an open redirect that enables attackers to redirect users to arbitrary external websites via a crafted URL. If exploited within SSO authentication flows, this could lead to exposure of session tokens and hijacking of user sessions. Users are advised to apply the necessary updates immediately.
Azərbaycanca: IBM Planning Analytics Local məhsulunda (versiya 2.1.0 - 2.1.21) open redirect zəifliyi aşkarlanıb. Təcavüzkar xüsusi hazırlanmış URL vasitəsilə istifadəçiləri istənilən xarici vebsayta yönləndirə bilər; bu, SSO autentifikasiya proseslərində sessiya tokenlərinin ifşasına və istifadəçi sessiyasının ələ keçirilməsinə səbəb ola bilər. İstifadəçilərə dərhal proqramı yeniləmələri tövsiyə olunur.
Related CVEs
link basis: shared vendor: IBM
FAQ2
Which IBM product is affected by CVE-2026-10545?
This open redirect vulnerability affects IBM Planning Analytics Local versions 2.1.0 through 2.1.21.
What can an attacker achieve by exploiting CVE-2026-10545 during SSO authentication?
By redirecting the user with a crafted URL, an attacker can expose session tokens within the SSO flow and hijack the user session.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.