XML External Entity Injection Vulnerability in IBM Business Automation Workflow
CVE-2026-12756
7.1HIGH
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 14 September 2026
What is CVE-2026-12756?
IBM Business Automation Workflow is susceptible to an XML external entity injection attack due to improper processing of XML data. This vulnerability may allow a remote attacker to exploit the system, potentially leaking sensitive information or causing excessive memory consumption, emphasizing the importance of securing XML elements against hostile external entities.
Affected Version(s)
Business Automation Workflow containers and traditional 26.0.0 <= 26.0.0 Interim Fix 001
Business Automation Workflow containers and traditional 25.0.0 <= 25.0.0 Interim Fix 005
Business Automation Workflow containers and traditional 24.0.1 <= 24.0.1 Interim Fix 008