CVE-2026-12749: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Patch 26.0.0-IF002 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Patch 25.0.0-IF006 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Patch 24.0.1-IF009 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Patch 24.0.0-IF010
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be an authenticated user of IBM Business Automation Workflow with the ability to embed content in the Web UI.
What is the likely security impact of successful exploitation?
An attacker can embed arbitrary JavaScript in the Web UI and alter its intended functionality. This can potentially disclose credentials within a trusted user session.