Unrated severityNVD Advisory· Published Aug 5, 2026
IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret
CVE-2026-18531
Description
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 9.2, 9.1, and 9.0
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7282362mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.