CVE-2026-12742

Summary

IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.

Affected Software

VendorProductVersion RangeStatus
IBMBusiness Automation Workflow containers and traditional26.0.0 <= 26.0.0 Interim Fix 001affected
IBMBusiness Automation Workflow containers and traditional25.0.0 <= 25.0.0 Interim Fix 005affected
IBMBusiness Automation Workflow containers and traditional24.0.1 <= 24.0.1 Interim Fix 008affected
IBMBusiness Automation Workflow containers and traditional24.0.0 <= 24.0.0 Interim Fix 009affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References