Description
IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: XPath injection allowing authenticated attackers to exfiltrate sensitive data and reveal XML document structure
Action: Patch Now
AI Analysis

Impact

The flaw is an XPath injection that enables an authenticated user to manipulate XML queries and gain unauthorized read access to application data. This can allow extraction of confidential information or full disclosure of XML document structure, a data‑disclosure and configuration‑exposure weakness classified as CWE‑643.

Affected Systems

Affected versions are IBM Cloud Pak for Business Automation releases 24.0.0 through interim fix 009, 24.0.1 through interim fix 008, 25.0.0 through interim fix 005, and 26.0.0 through interim fix 001. Each release series contains the specified interim fix that includes the vulnerability.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium impact. The EPSS is not available and the vulnerability is not listed in CISA KEV. Attackers require authenticated access; therefore the threat is constrained to accounts with permission to query the system’s XML data. In environments with strict role‑based access controls the attack surface may be limited, but any successful exploitation would result in confidential data exposure.

Generated by OpenCVE AI on September 16, 2026 at 01:01 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Remediation / FixIBM Cloud Pak for Business AutomationV26.0.0 - V26.0.0-IF001Apply security fix 26.0.0-IF002 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2600-if002 IBM Cloud Pak for Business AutomationV25.0.0 - V25.0.0-IF005Apply security fix 25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2500-if006 IBM Cloud Pak for Business AutomationV24.0.1 - V24.0.1-IF008Apply security fix 24.0.1-IF009 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2401-if009 IBM Cloud Pak for Business AutomationV24.0.0 - V24.0.0-IF009Apply security fix 24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2400-if010 Any open source library may be included in one or more sub-components of IBM Cloud Pak for Business Automation. Open source updates are not always synchronized across all components.


OpenCVE Recommended Actions

  • Install the appropriate interim fix for your deployed version (for example, 26.0.0‑IF001, 25.0.0‑IF005, 24.0.1‑IF008, or ).
  • Ensure that all open‑source sub‑components included in IBM Cloud Pak for Business Automation are updated to the patched state contained in the interim fixes to eliminate remaining injection vectors.
  • Limit the permissions of user roles so that only authorized personnel can issue XPath queries, thereby reducing the potential impact of exploitation.

Generated by OpenCVE AI on September 16, 2026 at 01:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
Title Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
First Time appeared Ibm
Ibm cloud Pak For Business Automation
Weaknesses CWE-643
CPEs cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_009:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_008:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Business Automation
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Cloud Pak For Business Automation
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T19:06:20.985Z

Reserved: 2026-06-10T11:56:00.828Z

Link: CVE-2026-11864

cve-icon Vulnrichment

Updated: 2026-09-15T19:06:11.450Z

cve-icon NVD

Status : Received

Published: 2026-09-15T18:17:12.527

Modified: 2026-09-15T19:17:15.370

Link: CVE-2026-11864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T01:15:17Z

Weaknesses
  • CWE-643

    Improper Neutralization of Data within XPath Expressions ('XPath Injection')