AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-12730

LOW · CVSS 3.8 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

IBM Business Automation Workflow versions 26.0.0, 25.0.0 (up to Interim Fix 005), and 24.0.1 (up to Interim Fix 007) are vulnerable due to improper hostname verification against server certificates. This flaw could enable an attacker to intercept connections by presenting a malicious server, potentially leading to unauthorized access or data exposure. Organizations using these specific versions should prioritize patching to mitigate the risk of man-in-the-middle attacks.

CVE
CVE-2026-12730
Severity
LOW
CVSS
3.8
EPSS
0.17%

Original NVD Description

IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.

Related CVEs

Other vulnerabilities affecting the same vendor(s)