Junglewise Threat Intelligence

CVE-2026-81859: IBM Enterprise Records broken cryptographic algorithm in CP4BA

CVE-2026-81859 · Severity: medium · CVSS 6.2 · Published 2026-09-04

Technologies: IBM Cloud Pak For Business Automation. Vendors: IBM.

Executive brief

IBM Enterprise Records is a data management component within Cloud Pak for Business Automation used to store and manage critical business documents and records. A cryptographic algorithm used in this component has known weaknesses, allowing a local attacker with system access to decrypt and read sensitive information that should be protected, potentially exposing confidential business data and customer records.

Technical details

The vulnerability stems from the use of a broken or risky cryptographic algorithm for encrypting sensitive data in IBM Enterprise Records. An attacker with local access to the system can exploit this weakness to decrypt protected information. The vulnerability requires local access rather than network access, limiting the threat surface to users or processes with direct system permissions. A patch or update is expected from IBM to replace the weak algorithm with a secure cryptographic implementation. The CVE-2026-81859 identifier tracks this issue.

Affected products

  • IBM Cloud Pak for Business Automation affected versions prior to August 2026 patch

Timeline

  • 2026-09-04: disclosed

References

Related threats