CVE-2026-81859: Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 26.0.0Patch 26.0.0-IF001 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 25.0.0Patch 25.0.0-IF005 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 24.0.1Patch 24.0.1-IF008 - Upgrade
Upgrade
IBM Cloud Pak for Business Automationto a version that resolves this vulnerability.Fixed in 24.0.0Patch 24.0.0-IF009
Event History
Frequently Asked Questions
Who can exploit this issue?
A local attacker can exploit the issue. The available information does not identify any remote attack path.
What is the impact if exploitation succeeds?
Successful exploitation could allow disclosure of sensitive information. No integrity or availability impact is indicated by the provided severity vector.
What should be prioritized for remediation?
Apply the IBM Cloud Pak for Business Automation iFixes for August 2026 referenced in the vendor advisory. The affected component is IBM Enterprise Records.