CVE-2026-11864
Received Received - Intake

XPath Injection in IBM Cloud Pak for Business Automation

Vulnerability report for CVE-2026-11864, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: IBM Corporation

Description

IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ibm cloud_pak_for_business_automation 26.0.0
ibm cloud_pak_for_business_automation 25.0.0
ibm cloud_pak_for_business_automation 24.0.1
ibm cloud_pak_for_business_automation 24.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-643 The product uses external input to dynamically construct an XPath expression used to retrieve data from an XML database, but it does not neutralize or incorrectly neutralizes that input. This allows an attacker to control the structure of the query.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an XPath injection flaw in IBM Cloud Pak for Business Automation versions 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009. An authenticated attacker could exploit this to exfiltrate sensitive application data or determine the structure of XML documents.

Detection Guidance

Detecting XPath injection vulnerabilities typically involves monitoring application logs for suspicious queries, unusual XML parsing errors, or unexpected data exfiltration patterns. Check for repeated failed authentication attempts or unauthorized access to sensitive data paths. Review logs for queries containing XPath expressions like '//', 'union', or 'select' with malicious intent.

Impact Analysis

An attacker could access sensitive data stored in the application or learn the structure of XML documents, potentially leading to further attacks or data breaches. The impact depends on the data processed by the affected software.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Exfiltration of data could result in legal penalties or loss of certification.

Mitigation Strategies

Apply the latest interim fixes for IBM Cloud Pak for Business Automation as specified in IBM's advisory. Restrict user permissions to minimize access to sensitive data. Implement input validation to sanitize XPath queries and use parameterized queries where possible. Monitor network traffic for unusual XML document requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11864. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart