CVE-2026-18531
CVE-2026-18531 is a medium-severity vulnerability in Ibm Maximo Application Suite with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-330.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 0% (31st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-330
- Affected product: Ibm Maximo Application Suite
- Published:
- Last modified:
Description
IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.
Frequently asked questions
- What is CVE-2026-18531?
- IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.
- How severe is CVE-2026-18531?
- CVE-2026-18531 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-18531 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (31st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-18531?
- CVE-2026-18531 primarily affects Ibm Maximo Application Suite. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-18531?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-18531 published?
- CVE-2026-18531 was published on 2026-08-05 and last updated on 2026-08-10.
References
Affected products (2)
- cpe:2.3:a:ibm:maximo_application_suite:*:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:maximo_application_suite:9.2:*:*:*:*:*:*:*
More vulnerabilities in Ibm Maximo Application Suite
- CVE-2025-36386 — Critical (CVSS 9.8): IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass…
- CVE-2024-27266 — High (CVSS 8.2): IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML…
- CVE-2025-2898 — High (CVSS 7.5): IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a…
- CVE-2024-22328 — High (CVSS 7.5): IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An…
- CVE-2021-38924 — High (CVSS 7.5): IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a…
- CVE-2021-29854 — High (CVSS 7.2): IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation…
All CVEs affecting Ibm Maximo Application Suite →
Other CWE-330 (Use of Insufficiently Random Values) vulnerabilities
- CVE-2023-22601 — Critical (CVSS 10.0): InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version…
- CVE-2026-25072 — Critical (CVSS 9.8): XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier…
- CVE-2026-27755 — Critical (CVSS 9.8): SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability…
- CVE-2026-27637 — Critical (CVSS 9.8): FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206,…
- CVE-2025-64097 — Critical (CVSS 9.8): NervesHub is a web service that allows users to manage over-the-air (OTA) firmware updates of devices in the field. A…
- CVE-2025-4607 — Critical (CVSS 9.8): The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up…
Browse all CWE-330 (Use of Insufficiently Random Values) vulnerabilities →