XPath Injection Vulnerability in IBM Cloud Pak for Business Automation
CVE-2026-11864
6.5MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 15 September 2026
What is CVE-2026-11864?
The IBM Cloud Pak for Business Automation software is exposed to an XPath injection vulnerability. This flaw allows an authenticated attacker to potentially exfiltrate sensitive application data and gain insights into the structure of the XML document. Timely patching and security measures are essential to mitigate the risks associated with this vulnerability.
Affected Version(s)
Cloud Pak for Business Automation 26.0.0 <= 26.0.0 Interim Fix 001
Cloud Pak for Business Automation 25.0.0 <= 25.0.0 Interim Fix 005
Cloud Pak for Business Automation 24.0.1 <= 24.0.1 Interim Fix 008