Description
IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-09-15
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting with potential credential disclosure
Action: Immediate Patch
AI Analysis

Impact

IBM Cloud Pak for Business Automation contains a persistent stored cross‑site scripting flaw that permits an authenticated user to inject arbitrary JavaScript into the web interface. The injected script runs in the victim’s browser with the victim’s credentials; it can modify the user interface or capture sensitive data, including credentials, that the user is authorized to see. The weakness is a classic example of improper input validation and storage, classified as CWE‑79. This flaw directly enables credential or data theft within a trusted session.

Affected Systems

IBM Cloud Pak for Business Automation is affected in releases 24.0.0, 24.0.1, 25.0.0 and 26.0.0, including the interim fix points listed for each version. Open‑source components integrated into the product can also introduce additional XSS vectors that may not be updated synchronously.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity. The EPSS score < 1% points to a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated, meaning the attacker must possess valid credentials or leverage another vulnerability to gain access. Once authenticated, a malicious script can execute in users’ browsers, potentially exposing credentials or facilitating other malicious activity. The risk remains moderate, especially where privileged user accounts are not tightly controlled.

Generated by OpenCVE AI on September 20, 2026 at 15:12 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Remediation / FixIBM Cloud Pak for Business AutomationV26.0.0 - V26.0.0-IF001Apply security fix 26.0.0-IF002 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2600-if002 IBM Cloud Pak for Business AutomationV25.0.0 - V25.0.0-IF005Apply security fix 25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2500-if006 IBM Cloud Pak for Business AutomationV24.0.1 - V24.0.1-IF008Apply security fix 24.0.1-IF009 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2401-if009 IBM Cloud Pak for Business AutomationV24.0.0 - V24.0.0-IF009Apply security fix 24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2400-if010 Any open source library may be included in one or more sub-components of IBM Cloud Pak for Business Automation. Open source updates are not always synchronized across all components.


OpenCVE Recommended Actions

  • Apply the IBM Cloud Pak for Business Automation patch that corresponds to your installed version (for example, upgrade to 26.0.0‑IF001 for v26.0.0; 25.0.0‑IF006 for v25.0.0; 24.0.1‑IF009 for v24.0.1; 24.0.0‑IF010 for v24.0.0).
  • Update all bundled open‑source libraries to their latest secure releases to eliminate additional XSS vectors introduced by those components.
  • Limit Web UI access to only the users who truly need it, reducing the authenticated attack surface.

Generated by OpenCVE AI on September 20, 2026 at 15:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_002:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_003:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_004:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_006:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_007:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_008:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_002:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_003:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_004:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_006:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_007:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:-:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_002:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_003:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_004:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:-:*:*:*:*:*:*

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
First Time appeared Ibm
Ibm cloud Pak For Business Automation
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_009:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_008:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Business Automation
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Cloud Pak For Business Automation
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-20T00:45:43.961Z

Reserved: 2026-06-19T19:15:20.212Z

Link: CVE-2026-12749

cve-icon Vulnrichment

Updated: 2026-09-20T00:42:23.151Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T18:17:14.813

Modified: 2026-09-23T20:12:42.703

Link: CVE-2026-12749

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')