XML External Entity Injection Vulnerability in IBM Business Automation Workflow
CVE-2026-12756

7.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 September 2026

What is CVE-2026-12756?

IBM Business Automation Workflow is susceptible to an XML external entity injection attack due to improper processing of XML data. This vulnerability may allow a remote attacker to exploit the system, potentially leaking sensitive information or causing excessive memory consumption, emphasizing the importance of securing XML elements against hostile external entities.

Affected Version(s)

Business Automation Workflow containers and traditional 26.0.0 <= 26.0.0 Interim Fix 001

Business Automation Workflow containers and traditional 25.0.0 <= 25.0.0 Interim Fix 005

Business Automation Workflow containers and traditional 24.0.1 <= 24.0.1 Interim Fix 008

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.