PatchSiren cyber security CVE debrief
CVE-2026-12750 IBM CVE debrief
IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. The vulnerability affects IBM Cloud Pak for Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0, as well as various interim fixes. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent exploitation.
- Vendor
- IBM
- Product
- Cloud Pak for Business Automation
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-23
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-23
Who should care
Defenders responsible for IBM Cloud Pak for Business Automation deployments should assess exposure and prioritize patching or mitigation to prevent exploitation. This includes operators, platform administrators, vulnerability management teams, and security teams. They should review system configurations and versions to ensure they are up-to-date and apply patches or mitigations provided by IBM.
Why it matters
CVE-2026-12750 is a stored cross-site scripting vulnerability in IBM Cloud Pak for Business Automation that allows authenticated users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent exploitation.
- Verify exposure and apply patches or mitigations to prevent exploitation
- Monitor Web UI activity for suspicious behavior
- Implement additional security controls to prevent exploitation
- Review system configurations and versions to ensure they are up-to-date
Technical summary
The vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session. Affected versions include IBM Cloud Pak for Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0, as well as various interim fixes. The vulnerability has a CVSS score of 6.4 and a severity of MEDIUM. Defenders should prioritize verifying exposure and applying patches or mitigations to prevent exploitation. The official CVE Program record and NVD detail page offer source-provided CVE metadata and vulnerability assessment.
Defensive priority
Defenders should prioritize verifying exposure and applying patches or mitigations to prevent exploitation.
Recommended defensive actions
- Verify exposure by reviewing system configurations and versions
- Apply patches or mitigations provided by IBM
- Monitor Web UI activity for suspicious behavior
- Implement additional security controls to prevent exploitation
- Review system configurations and versions to ensure they are up-to-date
- Track exceptions and retest remediated assets
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. The official CVE Program record and NVD detail page offer source-provided CVE metadata and vulnerability assessment. A patch and vendor advisory are available from IBM. Defenders should verify exposure and apply patches or mitigations to prevent exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12750 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12750
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12750 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12750
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7285931
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.