CVE-2026-1267 identifies a critical lack of proper access controls within IBM Planning Analytics Local versions 2.1.0 through 2.1.17, impacting installations on both IBM and Microsoft Windows. This vulnerability allows an authenticated, low-privileged attacker to gain unauthorized network-based access to sensitive application data and administrative functionalities. With a CVSSv3.1 score of 6.5 (Medium), it presents a high confidentiality impact due to its low attack complexity and absence of user interaction requirements. There is currently no evidence of active exploitation, public exploit code availability (e.g., Metasploit, ExploitDB), or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.1.0, <= 2.1.17CPE match | cpe:2.3:a:ibm:planning_analytics_local:*:*:*:*:*:*:*:* | ||
>= 2.1.0, < 2.1.18CPE matchmatch criteria | cpe:2.3:a:ibm:planning_analytics_local:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.