CVE-2026-11864

Summary

IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.

Affected Software

VendorProductVersion RangeStatus
IBMCloud Pak for Business Automation26.0.0 <= 26.0.0 Interim Fix 001affected
IBMCloud Pak for Business Automation25.0.0 <= 25.0.0 Interim Fix 005affected
IBMCloud Pak for Business Automation24.0.1 <= 24.0.1 Interim Fix 008affected
IBMCloud Pak for Business Automation24.0.0 <= 24.0.0 Interim Fix 009affected

Weaknesses

  • CWE-643: CWE-643 Improper Neutralization of Data within XPath Expressions ('XPath Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References