Description
IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.
Published: 2026-08-05
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Cloud Pak For Business Automation 24.0.0 through 26.0.0 can expose sensitive data when manifest files are read by a remote attacker, allowing them to retrieve confidential information that should not be publicly accessible. This problem arises from improper handling of configuration data and falls under the weakness of exposing sensitive information in externally accessible files (CWE-538). The consequences are that an attacker could learn credentials, internal IP addresses, or other environment secrets without needing additional access privileges, which could lead to further compromise of the business automation environment.

Affected Systems

The affected products are IBM Cloud Pak For Business Automation versions 24.0.0, 24.0.1, 25.0.0, and 26.0.0. These versions are listed in the CNA vendor/product information and are explicitly cited in the advisory links.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the vulnerability is considered exploitable remotely with no clear entry point documented; the EPSS score is not provided, and the vulnerability is not listed in the KEV catalog. The likely attack vector is a remote attacker gaining read access to exposed manifest files, which implies that the vulnerability can be triggered without local user interaction, as long as the manifest files are reachable over the network or through misconfigured file sharing. The risk is moderate but actionable, and remediation is strongly advised.

Generated by OpenCVE AI on August 5, 2026 at 17:39 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Business Automation Insights26.0.0Apply security fix   26.0.0-IF001 https://www.ibm.com/support/pages/node/7123944 IBM Business Automation Insights25.0.0Apply security fix   25.0.0-IF006 https://www.ibm.com/support/pages/node/7123944 IBM Business Automation Insights24.0.1Apply security fix   24.0.1-IF008 https://www.ibm.com/support/pages/node/7123944 IBM Business Automation Insights24.0.0Apply security fix   24.0.0-IF008 https://www.ibm.com/support/pages/node/7123944


OpenCVE Recommended Actions

  • Upgrade IBM Cloud Pak For Business Automation to the latest patched release (e.g., 24.0.0-IF008, 24.0.1-IF008, 25.0.0-IF006, or 26.0.0-IF001) as directed in IBM’s security advisory.
  • Move or secure the manifest files by storing them in a protected location and adjusting file permissions so that only authorized system components can read them.
  • Implement monitoring or logging of access attempts to sensitive configuration files, and investigate any anomalous or repeated read operations that could indicate exploitation.

Generated by OpenCVE AI on August 5, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.
Title Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automation Insights
First Time appeared Ibm
Ibm cloud Pak For Business Automation
Weaknesses CWE-538
CPEs cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Business Automation
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Cloud Pak For Business Automation
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-05T17:28:42.010Z

Reserved: 2026-06-19T21:57:31.285Z

Link: CVE-2026-12762

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T17:30:07Z

Weaknesses
  • CWE-538

    Insertion of Sensitive Information into Externally-Accessible File or Directory