CVE-2026-12751: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
IBM Business Automation Workflow is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Other sources
IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Patch V26.0.0-IF001 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Patch 26.0.0-IF002 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Patch 25.0.0-IF006 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Patch 24.0.1-IF009 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Patch 24.0.0-IF010