SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12758

MEDIUM · CVSS 5.4 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM Cloud Pak for Business Automation is vulnerable to a remote attack that can bypass authorization mechanisms, allowing unauthorized access to restricted endpoints due to improper validation of HTTP headers. This could lead to unauthorized actions within the application, potentially compromising sensitive data or functionality. Organizations using this product should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-12758
Severity
MEDIUM
CVSS
5.4
EPSS
0.30%

Original NVD Description

IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.