Junglewise Threat Intelligence

CVE-2026-12750: IBM Cloud Pak for Business Automation stored cross-site scripting

CVE-2026-12750 · Severity: medium · CVSS 6.4 · Published 2026-09-15

Executive brief

IBM Cloud Pak for Business Automation, a suite of tools for automating business processes, contains a stored cross-site scripting (XSS) vulnerability in its web interface. An authenticated attacker can inject malicious JavaScript code that persists in the application, allowing them to steal user credentials or modify functionality for any other user viewing the affected page.

Technical details

This is a stored (persistent) cross-site scripting vulnerability in the IBM Cloud Pak for Business Automation web UI. The vulnerability requires authentication to exploit, allowing an authenticated user to inject arbitrary JavaScript code that gets stored and executed in the browsers of other users visiting the affected pages. The attack can lead to session hijacking, credential theft, or unauthorized actions performed on behalf of legitimate users. The vulnerability was publicly disclosed on 2026-09-15 and assigned CVE-2026-12750 with a CVSS score of 6.4 (medium severity). IBM has issued security updates to address this issue.

Affected products

  • IBM Cloud Pak for Business Automation

Timeline

  • 2026-09-15: disclosed
  • 2026-08-01: advisory: Security bulletin issued for iFixes in August 2026

References

Related threats