CVE-2026-12762

Summary

IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.

Affected Software

VendorProductVersion RangeStatus
IBMCloud Pak For Business Automation24.0.0affected
IBMCloud Pak For Business Automation24.0.1affected
IBMCloud Pak For Business Automation25.0.0affected
IBMCloud Pak For Business Automation26.0.0affected

Weaknesses

  • CWE-538: CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References