Junglewise Threat Intelligence

CVE-2026-12749: IBM Cloud Pak for Business Automation stored XSS in Web UI

CVE-2026-12749 · Severity: medium · CVSS 6.4 · Published 2026-09-15

Executive brief

IBM Cloud Pak for Business Automation is a suite of business process and automation tools used by enterprises to streamline workflows. An authenticated user can inject malicious JavaScript code into the Web UI, which executes in the browsers of other trusted users, potentially allowing theft of login credentials or unauthorized actions within their sessions.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the Web UI component of IBM Cloud Pak for Business Automation. The vulnerability allows an authenticated attacker to embed arbitrary JavaScript code that persists in the application and executes when other users access the affected UI elements. While authentication is required to inject the payload, the XSS executes in the security context of other users' authenticated sessions, potentially enabling credential disclosure or session hijacking. Fix availability is indicated by the IBM Security Bulletin reference from August 2026.

Affected products

  • IBM Cloud Pak for Business Automation

Timeline

  • 2026-09-15: disclosed
  • 2026-08: advisory

References

Related threats