CVE-2026-12762: Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automation Insights
IBM Business Automation Insights could allow a remote attacker to obtain sensitive information exposed in manifest files.
Other sources
IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Business Automation Insightsto a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Business Automation Insightsto a version that resolves this vulnerability.Fixed in 25.0.0Patch 25.0.0-IF006 - Upgrade
Upgrade
IBM Business Automation Insightsto a version that resolves this vulnerability.Fixed in 24.0.1Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Business Automation Insightsto a version that resolves this vulnerability.Fixed in 24.0.0Patch 24.0.0-IF008
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12762?
CVE-2026-12762 has a medium severity score of 5.3.
How do I fix CVE-2026-12762?
To fix CVE-2026-12762, ensure that access to sensitive manifest files is properly restricted and not exposed externally.
What sensitive information is at risk with CVE-2026-12762?
CVE-2026-12762 allows attackers to potentially access sensitive information contained in manifest files.
Which versions of IBM Business Automation Insights are affected by CVE-2026-12762?
CVE-2026-12762 affects IBM Cloud Pak For Business Automation versions 24.0.0, 24.0.1, 25.0.0, and 26.0.0.
Can CVE-2026-12762 be exploited remotely?
Yes, CVE-2026-12762 can be exploited by a remote attacker to obtain sensitive information.