What is CVE-2026-15656?
CVE-2026-15656 affects IBM Maximo Application Suite versions 9.0, 9.1, and 9.2 where the 'Secure' attribute is not set on authorization tokens. Attackers can potentially steal cookie values by tricking users into clicking a malicious HTTP link. Users should upgrade to the latest version and enforce HTTPS connections.
Azərbaycanca: CVE-2026-15656 boşluğu IBM Maximo Application Suite-in 9.0, 9.1 və 9.2 versiyalarında "Secure" atributunun təyin edilməməsi ilə bağlıdır. Bu zəiflik təcavüzkarlara HTTP bağlantısı vasitəsilə authorization token-lərini ələ keçirməyə imkan verir. İstifadəçilərə məhsulu ən son versiyaya yeniləmək və yalnız HTTPS bağlantılarından istifadə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-522; shared vendor: IBM
FAQ2
Which versions of IBM Maximo Application Suite does CVE-2026-15656 affect?
This vulnerability affects IBM Maximo Application Suite versions 9.0, 9.1, and 9.2.
What measures should be taken to mitigate CVE-2026-15656?
Users should upgrade to the latest version and enforce HTTPS connections.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.