Authorization Bypass in IBM Cloud Pak for Business Automation
CVE-2026-12758
5.4MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 14 September 2026
What is CVE-2026-12758?
A vulnerability exists in IBM Cloud Pak for Business Automation that could enable a remote attacker to bypass authorization controls. This issue arises from improper validation of HTTP headers, allowing unauthorized access to restricted endpoints. It is essential for users of the product to apply available patches to mitigate potential risks. Further information can be found in the vendor advisory.
Affected Version(s)
Cloud Pak for Business Automation 26.0.0 <= 26.0.0 Interim Fix 001
Cloud Pak for Business Automation 25.0.0 <= 25.0.0 Interim Fix 005
Cloud Pak for Business Automation 24.0.1 <= 24.0.1 Interim Fix 008