CVE-2026-12751

Summary

IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

Affected Software

VendorProductVersion RangeStatus
IBMCloud Pak for Business Automation26.0.0 <= 26.0.0 Interim Fix 001affected
IBMCloud Pak for Business Automation25.0.0 <= 25.0.0 Interim Fix 005affected
IBMCloud Pak for Business Automation24.0.1 <= 24.0.1 Interim Fix 008affected
IBMCloud Pak for Business Automation24.0.0 <= 24.0.0 Interim Fix 009affected

Weaknesses

  • CWE-80: CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References