CVE-2026-13107: Multiple secuirty vulnerabilies addressed with IBM Business Automation Workflow August 2026
IBM Business Automation Workflow Advanced custom applications may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.
Other sources
IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 26.0.0-IF001Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 26.0.0-IF001Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 25.0.0-IF005Patch 25.0.0-IF005 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 25.0.0-IF005Patch 25.0.0-IF005 - Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 24.0.1-IF008Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 24.0.1-IF008Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Business Automation Workflow containersto a version that resolves this vulnerability.Fixed in 24.0.0-IF009Patch 24.0.0-IF009 - Upgrade
Upgrade
IBM Business Automation Workflow traditionalto a version that resolves this vulnerability.Fixed in 24.0.0-IF009Patch 24.0.0-IF009