Junglewise Threat Intelligence

CVE-2026-12752: IBM Business Automation Workflow XML external entity injection

CVE-2026-12752 · Severity: high · CVSS 7.1 · Published 2026-09-15

Executive brief

IBM Business Automation Workflow is a business process automation platform used to orchestrate complex workflows across organizations. An XML parsing vulnerability allows remote attackers to extract sensitive data or cause denial of service by submitting specially crafted XML files. This could lead to exposure of confidential business information or service outages affecting operational continuity.

Technical details

The vulnerability is an XML External Entity (XXE) injection flaw (CWE-611) in IBM Business Automation Workflow's XML processing logic, triggered when the application parses untrusted XML input without proper entity resolution restrictions. The attack is network-accessible and requires no authentication or user interaction. An attacker can supply malicious XML to read local files, access internal services, or trigger billion laughs/XML bomb attacks to exhaust memory and CPU resources. Patches are available through IBM's August 2026 security updates.

Affected products

  • IBM Business Automation Workflow

Timeline

  • 2026-09-15: disclosed
  • 2026-08: patched: August 2026 update

References

Related threats