CVE-2025-36262
MEDIUMIBM Planning Analytics Local <2.0.106, <2.1.13 - Info Disclosure
Title source: llmDescription
IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13 could allow a malicious privileged user to bypass the UI to gain unauthorized access to sensitive information due to the improper validation of input.
Scores
CVSS v3
4.9
EPSS
0.0006
EPSS Percentile
19.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1286
Status
published
Products (1)
ibm/planning_analytics_local
2.0.0 - 2.0.106
Published
Sep 30, 2025
Tracked Since
Feb 18, 2026