CVE-2026-12758: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
IBM Business Automation Workflow could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.
Other sources
IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF002 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 25.0.0Patch 25.0.0-IF005 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 25.0.0Patch 25.0.0-IF006 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 24.0.1Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 24.0.1Patch 24.0.1-IF009 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 24.0.0Patch 24.0.0-IF009 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 24.0.0Patch 24.0.0-IF010