CVE-2026-11864
IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-643
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- IBM Cloud Pak for Business Automation
- IBM Cloud Pak for Business Automation
- IBM Cloud Pak for Business Automation
- IBM Cloud Pak for Business Automation
Weakness type
Related vulnerabilities
- CVE-2024-39565 — Junos OS: J-Web: An unauthenticated, network-based attacker can perform XPATH injection attack against a device.
- CVE-2026-44962 — Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied
- CVE-2026-9390 — XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
- CVE-2020-25162 — B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus
- CVE-2026-24343 — Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions
- CVE-2026-40699 — BIG-IP Configuration utility vulnerability
- CVE-2025-11844 — XPath Injection in Hugging Face Smolagents search_item_ctrl_f Function
- CVE-2025-20218 — Cisco Secure Firepower Management Center Software XPATH Injection Vulnerability