CVE-2026-12749: IBM IBM Business Automation Workflow vulnerability
Published Sep 1, 2026
·Updated
IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
1 affected component
IBM IBM Business Automation Workflow
Event History
Sep 1, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be an authenticated user of IBM Business Automation Workflow with the ability to embed content in the Web UI.
2
What is the likely security impact of successful exploitation?
An attacker can embed arbitrary JavaScript in the Web UI and alter its intended functionality. This can potentially disclose credentials within a trusted user session.