Description
IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass via Improper HTTP Header Validation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper validation of HTTP headers that lets a remote attacker bypass the existing authorization controls in IBM Cloud Pak for Business Automation. By manipulating these headers, an attacker can invoke restricted API endpoints that normally require elevated privileges, potentially exposing sensitive data, altering business processes, or executing unauthorized commands. The weakness is classified as an authorization bypass, which can cause loss of confidentiality and integrity of business operations.

Affected Systems

IBM Cloud Pak for Business Automation versions 24.0.0, 24.0.1, 25.0.0, and 26.0.0 are impacted. 24.0.0 requires interim fix 009 or 010, 24.0.1 requires interim fix 008 or 009, 25.0.0 requires interim fix 005 or 006, and 26.0.0 requires interim fix 001 or 002. The fix updates address the header validation flaw and restore proper authorization checks.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. Exploitation is possible over the network through normal HTTP traffic, and no special conditions are currently known. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers can trivially trigger the flaw by sending crafted HTTP requests to privileged endpoints, so patching is recommended.

Generated by OpenCVE AI on September 17, 2026 at 19:17 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Remediation / FixIBM Cloud Pak for Business AutomationV26.0.0 - V26.0.0-IF001Apply security fix 26.0.0-IF002 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2600-if002 IBM Cloud Pak for Business AutomationV25.0.0 - V25.0.0-IF005Apply security fix 25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2500-if006 IBM Cloud Pak for Business AutomationV24.0.1 - V24.0.1-IF008Apply security fix 24.0.1-IF009 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2401-if009 IBM Cloud Pak for Business AutomationV24.0.0 - V24.0.0-IF009Apply security fix 24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2400-if010 Any open source library may be included in one or more sub-components of IBM Cloud Pak for Business Automation. Open source updates are not always synchronized across all components.


OpenCVE Recommended Actions

  • Apply the latest IBM Cloud Pak for Business Automation interim fix for the installed version (26.0.0-IF001 or 26.0.0-IF002; 25.0.0-IF005 or 25.0.0-IF006; 24.0.1-IF008 or 24.0.1-IF009; or 24.0.0-IF009 or 24.0.0-IF010).
  • If patching cannot be applied immediately, block or strictly sanitize the HTTP headers that influence authorization at the API gateway, proxy, or firewall level to prevent unauthorized endpoint access.
  • Maintain all open‑source components used within IBM Cloud Pak for Business Automation at their latest security‑patched releases and regularly review vendor advisories for additional updates.

Generated by OpenCVE AI on September 17, 2026 at 19:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.
Title Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
First Time appeared Ibm
Ibm cloud Pak For Business Automation
Weaknesses CWE-862
CPEs cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_009:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_008:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Business Automation
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Cloud Pak For Business Automation
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:46.140Z

Reserved: 2026-06-19T20:19:08.969Z

Link: CVE-2026-12758

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:35.286Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T22:16:56.643

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-12758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses