PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12750 IBM CVE debrief

IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. The vulnerability affects IBM Cloud Pak for Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0, as well as various interim fixes. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent exploitation.

Vendor
IBM
Product
Cloud Pak for Business Automation
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-23
Advisory published
2026-09-15
Advisory updated
2026-09-23

Who should care

Defenders responsible for IBM Cloud Pak for Business Automation deployments should assess exposure and prioritize patching or mitigation to prevent exploitation. This includes operators, platform administrators, vulnerability management teams, and security teams. They should review system configurations and versions to ensure they are up-to-date and apply patches or mitigations provided by IBM.

Why it matters

CVE-2026-12750 is a stored cross-site scripting vulnerability in IBM Cloud Pak for Business Automation that allows authenticated users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent exploitation.

  • Verify exposure and apply patches or mitigations to prevent exploitation
  • Monitor Web UI activity for suspicious behavior
  • Implement additional security controls to prevent exploitation
  • Review system configurations and versions to ensure they are up-to-date

Technical summary

The vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. Affected versions include IBM Cloud Pak for Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0, as well as various interim fixes. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent exploitation. The official CVE Program record and NVD detail page offer source-provided CVE metadata and vulnerability assessment.

Defensive priority

Defenders should prioritize verifying exposure and applying patches or mitigations to prevent exploitation.

Recommended defensive actions

  • Verify exposure by reviewing system configurations and versions
  • Apply patches or mitigations provided by IBM
  • Monitor Web UI activity for suspicious behavior
  • Implement additional security controls to prevent exploitation
  • Review system configurations and versions to ensure they are up-to-date
  • Track exceptions and retest remediated assets
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. The official CVE Program record and NVD detail page offer source-provided CVE metadata and vulnerability assessment. A patch and vendor advisory are available from IBM. Defenders should verify exposure and apply patches or mitigations to prevent exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12750 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12750

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12750 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12750

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.