SB2026100265 - Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services



SB2026100265 - Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services

Published: October 2, 2026

Security Bulletin ID SB2026100265
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 63% Low 38%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 vulnerabilities.


1) Cross-site request forgery (CVE-ID: CVE-2026-53663)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform cross-site request forgery actions.

The vulnerability exists due to cross-site request forgery in document request handling when processing PUT, PATCH, or DELETE requests in framework mode. A remote attacker can cause the victim's browser to send a crafted cross-site request to perform cross-site request forgery actions.

This issue does not affect applications using declarative mode or data mode.


2) Input validation error (CVE-ID: CVE-2025-68470)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to redirect the application to an external URL.

The vulnerability exists due to improper input validation in navigation path handling when processing attacker-supplied paths passed to navigate(), Link, or redirect(). A remote user can supply a crafted path to redirect the application to an external URL.

This issue only occurs when untrusted content is passed into navigation paths in application code.


3) Cross-site scripting (CVE-ID: CVE-2026-33245)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.

The vulnerability exists due to cross-site scripting in unstable RSC redirect handling when processing javascript: redirect targets from untrusted sources. A remote attacker can supply a crafted redirect target to execute arbitrary script in the victim's browser.

This only affects applications using the unstable RSC APIs.


4) Resource exhaustion (CVE-ID: CVE-2026-55685)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 5.4 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the __manifest endpoint when handling targeted unauthenticated requests. A remote user can send targeted requests to cause a denial of service.

Only Framework Mode applications are vulnerable.


5) Input validation error (CVE-ID: CVE-2026-53666)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger unexpected constructor execution on the client.

The vulnerability exists due to improper input validation in the SSR hydration process when processing attacker-supplied input that overwrites certain aspects of errors caught by SSR. A remote attacker can supply crafted input to trigger unexpected constructor execution on the client.

This only affects Framework Mode and Data Mode applications performing manual SSR and hydration, and does not impact Declarative Mode.


6) Cross-site scripting (CVE-ID: CVE-2026-53667)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.

The vulnerability exists due to improper input validation in the unstable RSC error handling path when processing redirects from untrusted sources. A remote attacker can supply a crafted redirect target to execute arbitrary script in the victim's browser.

This issue only affects applications using the unstable RSC APIs, and user interaction is required.


7) Open redirect (CVE-ID: CVE-2026-53668)

CWE-ID: CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')

CVSSv4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information or perform cross-site scripting.

The vulnerability exists due to improper input validation in redirect handling when processing attacker-crafted links. A remote attacker can supply a specially crafted link to trigger a redirect to an unexpected external location or an XSS vector to disclose sensitive information or perform cross-site scripting.

User interaction is required to follow the crafted link.


8) Open redirect (CVE-ID: CVE-2026-53669)

CWE-ID: CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to redirect users to an external site.

The vulnerability exists due to open redirect in navigation mechanisms when processing attacker-supplied paths. A remote attacker can supply a crafted path to trigger an unexpected external navigation to redirect users to an external site.


Remediation

Install update from vendor's website.