XML Entity Injection Vulnerability in IBM Business Automation Workflow
CVE-2026-13107

7.1HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 September 2026

What is CVE-2026-13107?

IBM Business Automation Workflow containers and traditional deployments utilize certain programming model artifacts that are susceptible to XML Entity Injection attacks. By exploiting this vulnerability, an attacker may manipulate XML input to inject arbitrary entities, potentially leading to unauthorized data access or service disruption. Organizations using IBM Business Automation Workflow are advised to review their implementation and apply necessary security patches to mitigate this risk.

Affected Version(s)

Business Automation Workflow containers and traditional 26.0.0 <= 26.0.0 Interim Fix 001

Business Automation Workflow containers and traditional 25.0.0 <= 25.0.0 Interim Fix 005

Business Automation Workflow containers and traditional 24.0.1 <= 24.0.1 Interim Fix 008

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.