CVE-2026-12756

Summary

IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Affected Software

VendorProductVersion RangeStatus
IBMBusiness Automation Workflow containers and traditional26.0.0 <= 26.0.0 Interim Fix 001affected
IBMBusiness Automation Workflow containers and traditional25.0.0 <= 25.0.0 Interim Fix 005affected
IBMBusiness Automation Workflow containers and traditional24.0.1 <= 24.0.1 Interim Fix 008affected
IBMBusiness Automation Workflow containers and traditional24.0.0 <= 24.0.0 Interim Fix 009affected

Weaknesses

  • CWE-611: CWE-611 Improper Restriction of XML External Entity Reference

References