Medium severity6.5NVD Advisory· Published Sep 15, 2026· Updated Sep 15, 2026
CVE-2026-11864
CVE-2026-11864
Description
IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.