CVE-2026-12759: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
IBM Business Automation Workflow could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.
Other sources
IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 25.0.0Patch 25.0.0-IF005 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 24.0.1Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 24.0.0Patch 24.0.0-IF009
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Deployments of IBM Business Automation Workflow are exposed if an authenticated user can access the affected functionality. The issue is a denial of service caused by uncontrolled resource consumption.
What level of access does an attacker need?
An attacker must be authenticated to exploit this issue. The provided information does not indicate that unauthenticated users can trigger it.