CVE-2025-36299Medium· 4.3▾ SunlitIBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system.
planning_analytics_local >= 2.1.0, < 2.1.15planning_analytics_workspace >= 2.1.0, < 2.1.15Upgrade past the affected range:
planning_analytics_local 2.1.15planning_analytics_workspace 2.1.15Connected by shared product, vendor, weakness, or advisory.
CVE-2025-36357High· 8.0IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system
CVE-2025-36076Medium· 4.3IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source code could be used by an authenticated user in further attacks against the system.
CVE-2026-97680High· 8.3IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to improper access control in the vertex result caching subsystem.
CVE-2026-97679High· 8.8IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation.
CVE-2026-97678High· 8.8IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation.
CVE-2026-97676High· 8.8IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code, resulting in a sandbox escape.