Executive brief
IBM Cloud Pak for Business Automation is an enterprise platform used to automate complex business processes and workflows. A vulnerability in HTTP header validation allows remote attackers to bypass authorization controls and invoke restricted endpoints, potentially enabling unauthorized access to sensitive business operations and data.
Technical details
The vulnerability is an authorization bypass due to improper validation of HTTP headers in IBM Cloud Pak for Business Automation. An unauthenticated remote attacker can craft malicious HTTP requests with crafted headers to bypass authorization checks and access restricted endpoints. The root cause lies in insufficient header validation logic that fails to properly authenticate or authorize requests before allowing access to sensitive functionality. This is a network-reachable vulnerability requiring no special preconditions, allowing an attacker to invoke restricted API endpoints or administrative functions that should be protected.
Affected products
- IBM Cloud Pak for Business Automation
Timeline
- 2026-09-14: disclosed
- 2026-08: advisory