CVE-2026-12752
published 2026-09-15CVE-2026-12752: IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote…
PriorityP345high7.1CVSS 3.1
AVNACLPRLUINSUCHINAL
EPSS
0.50%
41.6th percentile
IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | business_automation_workflow_containers_and_traditional | 24.0.0 – 24.0.0 Interim Fix 009 | — |
| ibm | business_automation_workflow_containers_and_traditional | 24.0.1 – 24.0.1 Interim Fix 008 | — |
| ibm | business_automation_workflow_containers_and_traditional | 25.0.0 – 25.0.0 Interim Fix 005 | — |
| ibm | business_automation_workflow_containers_and_traditional | 26.0.0 – 26.0.0 Interim Fix 001 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Business Automation Workflow xml external entity reference (EUVD-2026-78865)
vuldb·2026-09-15·CVSS 7.1
CVE-2026-12752 [HIGH] IBM Business Automation Workflow xml external entity reference (EUVD-2026-78865)
A vulnerability marked as critical has been reported in IBM Business Automation Workflow. The affected element is an unknown function. This manipulation causes xml external entity reference.
This vulnerability appears as CVE-2026-12752. The attack may be initiated remotely. There is no available exploit.
GHSA
IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data.
ghsa_unreviewed·2026-09-15
CVE-2026-12752 [HIGH] CWE-611 IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data.
IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-15
Published