Junglewise Threat Intelligence

CVE-2026-13107: IBM Business Automation Workflow XML Entity Injection in programming models

CVE-2026-13107 · Severity: high · CVSS 7.1 · Published 2026-09-14

Executive brief

IBM Business Automation Workflow's advanced custom applications use programming model artifacts that are vulnerable to XML Entity Injection (XXE) attacks by default. An authenticated user could exploit this to read sensitive files or disrupt service availability, potentially exposing confidential business data or causing operational disruptions.

Technical details

This vulnerability is an XXE (XML External Entity Injection) flaw classified under CWE-611 affecting IBM Business Automation Workflow. The root cause is improper restriction of XML external entity references in programming model artifacts used by advanced custom applications. The attack requires network access and authenticated user credentials (PR:L per CVSS vector). An attacker can read sensitive files from the server and cause denial of service through resource consumption. IBM has released a patch as part of the August 2026 security update.

Affected products

  • IBM Business Automation Workflow

Timeline

  • 2026-09-14: disclosed

References

Related threats