CVE-2026-12758
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Summary
IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Cloud Pak for Business Automation | 26.0.0 <= 26.0.0 Interim Fix 001 | affected |
| IBM | Cloud Pak for Business Automation | 25.0.0 <= 25.0.0 Interim Fix 005 | affected |
| IBM | Cloud Pak for Business Automation | 24.0.1 <= 24.0.1 Interim Fix 008 | affected |
| IBM | Cloud Pak for Business Automation | 24.0.0 <= 24.0.0 Interim Fix 009 | affected |
Weaknesses
- CWE-862: CWE-862 Missing Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.