Description
IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: XPath injection allowing authenticated attackers to exfiltrate sensitive data via crafted XPath queries
Action: Patch Now
AI Analysis

Impact

The vulnerability is an XPath injection flaw in IBM Cloud Pak for Business Automation that permits an authenticated attacker to construct malicious XPath queries against the application's XML data store. By injecting specially crafted expressions, a legitimate user can read or infer the contents of sensitive documents or reveal the structure of the XML schema. The flaw is present in the 26.0.0 release with Interim Fix 001, 25.0.0 with Interim Fix 005, 24.0.1 with Interim Fix 008, and 24.0.0 with Interim Fix 009, and may affect any open‑source sub‑components bundled within the product if they are not updated to the patched versions.

Affected Systems

IBM Cloud Pak for Business Automation versions 26.0.0 (Interim Fix 001), 25.0.0 (Interim Fix 005), 24.0.1 (Interim Fix 008), and 24.0.0 (Interim Fix 009). Any open‑source libraries inside the product may also be vulnerable if they are not synchronized with the interim fixes.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity risk, while the EPSS score of <1% shows a very low but non‑zero probability of exploitation. The flaw is not listed in the CISA KEV catalog, suggesting it is not widely exploited in the wild. Attackers must be authenticated and must have sufficient permissions to execute XPath queries; with strict role‑based access control the attack surface is limited, but privileged accounts can still exploit the issue.

Generated by OpenCVE AI on September 20, 2026 at 14:51 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Remediation / FixIBM Cloud Pak for Business AutomationV26.0.0 - V26.0.0-IF001Apply security fix 26.0.0-IF002 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2600-if002 IBM Cloud Pak for Business AutomationV25.0.0 - V25.0.0-IF005Apply security fix 25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2500-if006 IBM Cloud Pak for Business AutomationV24.0.1 - V24.0.1-IF008Apply security fix 24.0.1-IF009 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2401-if009 IBM Cloud Pak for Business AutomationV24.0.0 - V24.0.0-IF009Apply security fix 24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2400-if010 Any open source library may be included in one or more sub-components of IBM Cloud Pak for Business Automation. Open source updates are not always synchronized across all components.


OpenCVE Recommended Actions

  • Apply the IBM interim fix that matches your deployment: 26.0.0‑IF001 for v26.0.0, 25.0.0‑IF005 for v25.0.0, 24.0.1‑IF008 for v24.0.1, and 24.0.0‑IF009 for v24.0.0, following the IBM support readme pages and installing the patches.
  • Ensure all open‑source sub‑components bundled in the product are updated to the versions included in the interim fixes so that no component remains vulnerable.
  • Restrict permissions for executing XPath queries by tightening role‑based access controls so that only the minimum set of privileged users can run such queries.

Generated by OpenCVE AI on September 20, 2026 at 14:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
Title Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
First Time appeared Ibm
Ibm cloud Pak For Business Automation
Weaknesses CWE-643
CPEs cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_009:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_008:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Business Automation
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Cloud Pak For Business Automation
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T19:06:20.985Z

Reserved: 2026-06-10T11:56:00.828Z

Link: CVE-2026-11864

cve-icon Vulnrichment

Updated: 2026-09-15T19:06:11.450Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:12.527

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-11864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-643

    Improper Neutralization of Data within XPath Expressions ('XPath Injection')