CVE-2026-12752: Multiple security vulnerabilities addressed with IBM Business Automation Workflow August 2026
IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource.
Other sources
IBM Business Automation Workflow is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 26.0.0-IF002Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 26.0.0-IF002Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 25.0.0-IF006Patch 25.0.0-IF005 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 25.0.0-IF006Patch 25.0.0-IF005 - Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 24.0.1-IF009Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 24.0.1-IF009Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 24.0.0-IF010Patch 24.0.0-IF009 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 24.0.0-IF010Patch 24.0.0-IF009
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker needs remote network access and the ability to cause IBM Business Automation Workflow to process XML data. The CVSS vector indicates low attack complexity, requires low privileges, and does not require user interaction.
What is the likely impact of successful exploitation?
Successful XXE exploitation could expose sensitive information or consume memory resources. The supplied CVSS vector rates confidentiality impact as high and availability impact as low, with no integrity impact.
Which deployment types are affected?
The issue affects both IBM Business Automation Workflow containers and traditional deployments when they process XML data.