Description
CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm.
Published: 2026-09-04
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Patch Now
AI Analysis

Impact

The vulnerability in IBM Cloud Pak for Business Automation stems from a broken or risky cryptographic algorithm within the IBM Enterprise Records component. A local attacker who can access the system is able to extract sensitive information, such as stored records or credentials, through the compromised cryptographic process. The weakness is categorized as improper cryptographic algorithm usage (CWE-327) and directly compromises confidentiality of data stored by the application.

Affected Systems

IBM Cloud Pak for Business Automation versions 24.0.0, 24.0.1, 25.0.0, and 26.0.0 are affected. Each version has an interim security fix: 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, and 26.0.0-IF001, along with subsequent security fix releases such as IF002 and IF006. All affected installations should be updated to the latest interim fix available for the specific version. Open‑source libraries used in sub‑components may also contain independent vulnerabilities, but the CVE is specifically addressed by the IBM fixes.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity. Exploitation requires local system access; it is not remotely exploitible and therefore the threat is limited to compromised or privileged users. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits at the time of analysis. Nonetheless, the potential for sensitive data exposure warrants immediate remediation.

Generated by OpenCVE AI on September 4, 2026 at 17:52 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Affected Product(s)Version(s)Remediation / FixIBM Cloud Pak for Business AutomationV26.0.0 - V26.0.0-IF001Apply security fix 26.0.0-IF002 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2600-if002 IBM Cloud Pak for Business AutomationV25.0.0 - V25.0.0-IF005Apply security fix 25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2500-if006 IBM Cloud Pak for Business AutomationV24.0.1 - V24.0.1-IF008Apply security fix 24.0.1-IF009 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2401-if009 IBM Cloud Pak for Business AutomationV24.0.0 - V24.0.0-IF009Apply security fix 24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2400-if010 Any open source library may be included in one or more sub-components of IBM Cloud Pak for Business Automation. Open source updates are not always synchronized across all components. The CVE in this bulletin are specifically addressed by


OpenCVE Recommended Actions

  • Apply the latest IBM Cloud Pak for Business Automation security fix for your installation (e.g., 26.0.0-IF001 or IF002 for V26.0.0, 25.0.0-IF005 or IF006 for V25.0.0, 24.0.1-IF008 for V24.0.1, 24.0.0-IF009 or IF010 for V24.0.0).
  • If an update cannot be applied immediately, isolate the IBM Enterprise Records service or restrict local user access to the component to prevent exploitation of the cryptographic flaw.
  • Conduct a scan of all sub‑components and open‑source libraries used by IBM Cloud Pak for Business Automation to ensure they are at the latest patched versions and that no additional cryptographic weaknesses exist.

Generated by OpenCVE AI on September 4, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm.
Title Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.
First Time appeared Ibm
Ibm cloud Pak For Business Automation
Weaknesses CWE-327
CPEs cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_009:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_008:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm cloud Pak For Business Automation
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Cloud Pak For Business Automation
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T18:25:05.317Z

Reserved: 2026-08-27T16:44:43.404Z

Link: CVE-2026-81859

cve-icon Vulnrichment

Updated: 2026-09-04T17:39:56.065Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T15:17:35.690

Modified: 2026-09-08T14:17:08.940

Link: CVE-2026-81859

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:30:06Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm