Hostname Verification Flaw in IBM Business Automation Workflow Products
CVE-2026-12730
3.8LOW
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-12730?
IBM Business Automation Workflow suffers from a vulnerability where hostname validation against the server certificate is inadequately performed. This oversight may allow an attacker to intercept connections by redirecting traffic to a malicious server, posing significant risks to data integrity and confidentiality. It is crucial for users to address this issue by applying the necessary patches and ensuring secure configurations.
Affected Version(s)
Business Automation Workflow containers and traditional 26.0.0
Business Automation Workflow containers and traditional 25.0.0 <= 25.0.0 Interim Fix 005
Business Automation Workflow containers and traditional 24.0.1 <= 24.0.1 Interim Fix 007