CVE-2026-12758
Received Received - Intake

IBM Cloud Pak for Business Automation Authorization Bypass

Vulnerability report for CVE-2026-12758, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-15

Assigner: IBM Corporation

Description

IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-15
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm cloud_pak_for_business_automation to 2026-08-01 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Cloud Pak for Business Automation has a vulnerability where a remote attacker could bypass authorization checks and access restricted endpoints. This happens because the system does not properly validate HTTP headers, allowing unauthorized actions to be performed.

Detection Guidance

Detecting this vulnerability requires checking for improper HTTP header validation in IBM Cloud Pak for Business Automation. Monitor network traffic for unauthorized endpoint invocations and inspect HTTP headers for manipulation attempts. Check IBM's security bulletins for patches and validate that all endpoints enforce proper authorization checks.

Impact Analysis

This vulnerability could allow an attacker to gain unauthorized access to sensitive data or perform actions they should not be able to, potentially leading to data breaches or system misuse. The impact depends on the privileges of the compromised account.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using this software may face legal and regulatory penalties if data breaches occur.

Mitigation Strategies

Apply IBM's official patches or updates for Cloud Pak for Business Automation to fix the HTTP header validation issue. Review and restrict access to sensitive endpoints to prevent unauthorized invocation. Monitor network traffic for unusual requests targeting restricted paths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12758. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart