Junglewise Threat Intelligence

CVE-2026-12756: IBM Business Automation Workflow XML external entity injection

CVE-2026-12756 · Severity: high · CVSS 7.1 · Published 2026-09-14

Executive brief

IBM Business Automation Workflow is an enterprise application platform used to automate business processes and document management. A vulnerability allows remote attackers to exploit XML processing to extract sensitive information or cause service disruptions by consuming memory resources without authentication barriers.

Technical details

The vulnerability is an XML External Entity (XXE) injection in IBM Business Automation Workflow's XML processing component. An attacker can send specially crafted XML input to trigger entity expansion or file access attacks. The vulnerability requires network access to the XML parser endpoint but does not require prior authentication in the base attack vector. Successful exploitation can lead to information disclosure (sensitive files, configuration data) or denial of service through entity expansion attacks that exhaust memory. Patches are available as part of IBM's August 2026 security update bundle.

Affected products

  • IBM Business Automation Workflow <UNKNOWN>

Timeline

  • 2026-09-14: disclosed
  • 2026-08: patched: Fix included in August 2026 security update

References

Related threats