CVE-2026-12742: Multiple secuirty vulnerabilies addressed with IBM Business Automation Workflow August 2026
IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.
Other sources
IBM Business Automation Workflow could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Business Automation Workflow (containers)to a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Business Automation Workflow (traditional)to a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF002 - Upgrade
Upgrade
IBM Business Automation Workflow (containers)to a version that resolves this vulnerability.Fixed in 25.0.0Patch 25.0.0-IF005 - Upgrade
Upgrade
IBM Business Automation Workflow (traditional)to a version that resolves this vulnerability.Fixed in 25.0.0Patch 25.0.0-IF006 - Upgrade
Upgrade
IBM Business Automation Workflow (containers)to a version that resolves this vulnerability.Fixed in 24.0.1Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Business Automation Workflow (traditional)to a version that resolves this vulnerability.Fixed in 24.0.1Patch 24.0.1-IF009 - Upgrade
Upgrade
IBM Business Automation Workflow (containers)to a version that resolves this vulnerability.Fixed in 24.0.0Patch 24.0.0-IF010 - Upgrade
Upgrade
IBM Business Automation Workflow (traditional)to a version that resolves this vulnerability.Fixed in 24.0.0Patch 24.0.0-IF009
Event History
Frequently Asked Questions
What level of access does an attacker need?
An attacker needs to be authenticated to IBM Business Automation Workflow. No user interaction is required.
Which deployment models are affected?
The issue affects IBM Business Automation Workflow containers and traditional deployments.
What could an attacker do if they exploit this issue?
An authenticated attacker could trigger import actions that should be restricted because authorization controls are missing. The reported impact includes low confidentiality and integrity impact, with no availability impact.