CVE-2026-12756: Multiple secuirty vulnerabilies addressed with IBM Business Automation Workflow August 2026
IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Other sources
IBM Business Automation Workflow is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Business Automation Workflow (containers)to a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Business Automation Workflow (traditional)to a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Business Automation Workflow (containers)to a version that resolves this vulnerability.Fixed in 25.0.0Patch 25.0.0-IF005 - Upgrade
Upgrade
IBM Business Automation Workflow (traditional)to a version that resolves this vulnerability.Fixed in 25.0.0Patch 25.0.0-IF005 - Upgrade
Upgrade
IBM Business Automation Workflow (containers)to a version that resolves this vulnerability.Fixed in 24.0.1Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Business Automation Workflow (traditional)to a version that resolves this vulnerability.Fixed in 24.0.1Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Business Automation Workflow (containers)to a version that resolves this vulnerability.Fixed in 24.0.0Patch 24.0.0-IF009 - Upgrade
Upgrade
IBM Business Automation Workflow (traditional)to a version that resolves this vulnerability.Fixed in 24.0.0Patch 24.0.0-IF009
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires low attack complexity, and requires low privileges. No user interaction is required.
Which deployments should be evaluated for exposure?
Both IBM Business Automation Workflow container deployments and traditional deployments should be evaluated, particularly where the product processes XML data.