CyberRota Analysis
AI-GeneratedIBM Cloud Pak for Business Automation is vulnerable to a remote attack that can bypass authorization mechanisms, allowing unauthorized access to restricted endpoints due to improper validation of HTTP headers. This could lead to unauthorized actions within the application, potentially compromising sensitive data or functionality. Organizations using this product should prioritize remediation to mitigate the risk of exploitation.
CVE
CVE-2026-12758
Severity
MEDIUM
CVSS
5.4
EPSS
0.30%
Original NVD Description
IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.