CVE-2026-12756
moderateXXE Vulnerability in IBM Business Automation Workflow Could Leak Sensitive Files
IBM Business Automation Workflow, in both its containerized and traditional (on-premises) deployments, contains an XML external entity injection (XXE) flaw (CWE-611) that is triggered when the product parses attacker-supplied XML data. Because the CVSS vector requires only low privileges (PR:L), an authenticated remote attacker with valid user access can submit crafted XML containing malicious external entity definitions. Successful exploitation lets the attacker read sensitive files or data from the host (high confidentiality impact) and potentially exhaust memory resources, degrading or disrupting the service (low availability impact); integrity is not affected. All organizations running the affected container or traditional editions of Business Automation Workflow are exposed, particularly where business users can upload or submit XML content into processes or services. As of this writing there is no known public proof of concept and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Apply the fix from IBM's official security bulletin for this CVE to all Business Automation Workflow container and traditional deployments once the patched versions are confirmed. As an interim mitigation, disable or restrict DTD and external entity resolution in XML parsers handling user-supplied XML, and limit which authenticated users and integration endpoints can submit XML content. Review logs for unexpected file-read behavior or memory exhaustion on process/service nodes that ingest XML, and verify that workflow servers cannot reach arbitrary internal file paths or external DTD endpoints.
| IBM Business Automation Workflow (containers) | — |
| IBM Business Automation Workflow (traditional) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.