Description
IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via uncontrolled resource consumption by an authenticated user
Action: Patch Now
AI Analysis

Impact

IBM Cloud Pak for Business Automation contains a flaw that allows an authenticated user to trigger a denial of service by consuming an excessive amount of system resources. The vulnerability is characterized by misuse of resource allocation, leading to service degradation or interruption. The description does not explicitly state any privilege escalation or data exfiltration capabilities, so the impact is limited to availability.

Affected Systems

The affected product is IBM Cloud Pak for Business Automation. The vulnerability affects multiple releases: version 26.0.0 (interim fix IF001), 25.0.0 (interim fix IF006), 24.0.1 (interim fix IF009), and 24.0.0 (interim fix IF010). The issue may involve open source libraries that are part of the deployment, so any component containing those libraries could be impacted, depending on how the product is configured.

Risk and Exploitability

The CVSS score of 6.5 places this vulnerability in the medium severity range. Although the EPSS score of < 1% indicates a very low likelihood of exploitation and the vulnerability is not listed in the CISA KEV catalog, the requirement for authentication suggests that the attack surface is limited to users who already have valid access to the system. The lack of evidence for widespread exploitation does not eliminate the risk, because an insider or compromised account could exploit the flaw to disrupt service. Enterprises should prioritize mitigation due to the potential for significant availability impact.

Generated by OpenCVE AI on September 17, 2026 at 19:17 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Remediation / FixIBM Cloud Pak for Business AutomationV26.0.0 - V26.0.0-IF001Apply security fix 26.0.0-IF002 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2600-if002 IBM Cloud Pak for Business AutomationV25.0.0 - V25.0.0-IF005Apply security fix 25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2500-if006 IBM Cloud Pak for Business AutomationV24.0.1 - V24.0.1-IF008Apply security fix 24.0.1-IF009 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2401-if009 IBM Cloud Pak for Business AutomationV24.0.0 - V24.0.0-IF009Apply security fix 24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2400-if010 Any open source library may be included in one or more sub-components of IBM Cloud Pak for Business Automation. Open source updates are not always synchronized across all components.


OpenCVE Recommended Actions

  • Apply the IBM Cloud Pak for Business Automation interim fix for your current version—e.g., update to v26.0.0-IF001 if running 26.0.0, to v25.0.0-IF006 if running 25.0.0, to v24.0.1-IF009 if running 24.0.1, or to v24.0.0-IF010 if running 24.0.0.
  • If a patch update is not immediately feasible, isolate the affected service from the broader network and restrict the number of concurrently running processes to mitigate resource exhaustion.
  • Review and harden the authentication controls for privileged accounts, ensuring that only trusted users have the ability to interact with resource‑intensive components, and enforce rate limits or quotas wherever possible.

Generated by OpenCVE AI on September 17, 2026 at 19:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.
Title Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
First Time appeared Ibm
Ibm cloud Pak For Business Automation
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_009:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_008:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Business Automation
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Cloud Pak For Business Automation
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:31:46.297Z

Reserved: 2026-06-19T20:23:05.385Z

Link: CVE-2026-12759

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:37.325Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T22:16:56.797

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-12759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption