Junglewise Threat Intelligence

CVE-2026-12742: IBM Business Automation Workflow missing authorization in import

CVE-2026-12742 · Severity: medium · CVSS 5.4 · Published 2026-09-15

Executive brief

IBM Business Automation Workflow is a business process automation platform used to manage and execute enterprise workflows. An authenticated attacker could bypass authorization controls to trigger restricted import actions, potentially allowing unauthorized modification or injection of business logic into workflow definitions.

Technical details

A missing authorization control vulnerability in IBM Business Automation Workflow allows authenticated users to trigger import actions that should be restricted. The vulnerability affects both containerized and traditional deployments. An attacker who has valid authentication credentials can invoke import functionality without proper permission validation, potentially leading to unauthorized modification of workflow configurations or data. The fix requires implementing proper authorization checks on import operations.

Affected products

  • IBM Business Automation Workflow

Timeline

  • 2026-09-15: disclosed

References

Related threats