CVE-2026-13365 PUBLISHED

IBM Planning Analytics Local is affected by security vulnerabilities

Assigner: ibm
Reserved: 25.06.2026 Published: 13.08.2026 Updated: 13.08.2026

IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
CVSS Score: 7.1

Product Status

Vendor IBM
Product Planning Analytics
Versions
  • Version 2.0 is affected
  • Version 2.1 is affected

Solutions

It is strongly recommended that you apply the most recent security updates: 

Affected Product(s)Version(s)FixIBM Planning Analytics Local2.1.0 - 2.1.22 IBM Planning Analytics Local 2.1.23 is now available for download from Fix Central https://w3.ibm.com/w3publisher/capa-release-announcements/2026-releases/pa-2026-releases

IBM Planning Analytics Cloud environment has been remediated.

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE