{"api_version":"1","generated_at":"2026-09-18T13:50:12+00:00","cve":"CVE-2026-11864","urls":{"html":"https://cve.report/CVE-2026-11864","api":"https://cve.report/api/cve/CVE-2026-11864.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-11864","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-11864"},"summary":{"title":"Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026.","description":"IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-09-15 18:17:12","updated_at":"2026-09-16 19:24:58"},"problem_types":["CWE-643","CWE-643 CWE-643 Improper Neutralization of Data within XPath Expressions ('XPath Injection')"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285931","name":"https://www.ibm.com/support/pages/node/7285931","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-11864","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11864","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Cloud Pak for Business Automation","version":"affected 26.0.0 26.0.0 Interim Fix 001 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cloud Pak for Business Automation","version":"affected 25.0.0 25.0.0 Interim Fix 005 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cloud Pak for Business Automation","version":"affected 24.0.1 24.0.1 Interim Fix 008 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Cloud Pak for Business Automation","version":"affected 24.0.0 24.0.0 Interim Fix 009 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerability now.\n\n\n\nAffected Product(s)Version(s)Remediation / FixIBM Cloud Pak for Business AutomationV26.0.0 - V26.0.0-IF001Apply security fix  26.0.0-IF002 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2600-if002 IBM Cloud Pak for Business AutomationV25.0.0 - V25.0.0-IF005Apply security fix  25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2500-if006 IBM Cloud Pak for Business AutomationV24.0.1 - V24.0.1-IF008Apply security fix  24.0.1-IF009 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2401-if009 IBM Cloud Pak for Business AutomationV24.0.0 - V24.0.0-IF009Apply security fix  24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2400-if010 \n\n\n\nAny open source library may be included in one or more sub-components of IBM Cloud Pak for Business Automation. Open source updates are not always synchronized across all components.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Vinayachandran.Sasidharan@ibm.com","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"11864","cve":"CVE-2026-11864","epss":"0.003710000","percentile":"0.307640000","score_date":"2026-09-16","updated_at":"2026-09-17 00:07:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-11864","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-15T19:06:07.053018Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-15T19:06:20.985Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:interim_fix_001:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_005:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_008:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_009:*:*:*:*:*:*"],"product":"Cloud Pak for Business Automation","vendor":"IBM","versions":[{"lessThanOrEqual":"26.0.0 Interim Fix 001","status":"affected","version":"26.0.0","versionType":"semver"},{"lessThanOrEqual":"25.0.0 Interim Fix 005","status":"affected","version":"25.0.0","versionType":"semver"},{"lessThanOrEqual":"24.0.1 Interim Fix 008","status":"affected","version":"24.0.1","versionType":"semver"},{"lessThanOrEqual":"24.0.0 Interim Fix 009","status":"affected","version":"24.0.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Vinayachandran.Sasidharan@ibm.com"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.</p>"}],"value":"IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-643","description":"CWE-643 Improper Neutralization of Data within XPath Expressions ('XPath Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-15T17:30:12.589Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7285931"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<div><p>IBM strongly recommends addressing the vulnerability now.</p></div><div><table><thead><tr><td>Affected Product(s)</td><td>Version(s)</td><td>Remediation / Fix</td></tr></thead><tbody><tr><td>IBM Cloud Pak for Business Automation</td><td>V26.0.0 - V26.0.0-IF001</td><td>Apply security fix <a href=\"https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2600-if002\" rel=\"nofollow\">26.0.0-IF002</a></td></tr><tr><td>IBM Cloud Pak for Business Automation</td><td>V25.0.0 - V25.0.0-IF005</td><td>Apply security fix <a href=\"https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2500-if006\" rel=\"nofollow\">25.0.0-IF006</a></td></tr><tr><td>IBM Cloud Pak for Business Automation</td><td>V24.0.1 - V24.0.1-IF008</td><td>Apply security fix <a href=\"https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2401-if009\" rel=\"nofollow\">24.0.1-IF009</a></td></tr><tr><td>IBM Cloud Pak for Business Automation</td><td>V24.0.0 - V24.0.0-IF009</td><td>Apply security fix <a href=\"https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2400-if010\" rel=\"nofollow\">24.0.0-IF010</a></td></tr></tbody></table></div><p>Any open source library may be included in one or more sub-components of IBM Cloud Pak for Business Automation. Open source updates are not always synchronized across all components.</p>"}],"value":"IBM strongly recommends addressing the vulnerability now.\n\n\n\nAffected Product(s)Version(s)Remediation / FixIBM Cloud Pak for Business AutomationV26.0.0 - V26.0.0-IF001Apply security fix  26.0.0-IF002 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2600-if002 IBM Cloud Pak for Business AutomationV25.0.0 - V25.0.0-IF005Apply security fix  25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2500-if006 IBM Cloud Pak for Business AutomationV24.0.1 - V24.0.1-IF008Apply security fix  24.0.1-IF009 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2401-if009 IBM Cloud Pak for Business AutomationV24.0.0 - V24.0.0-IF009Apply security fix  24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-cloud-pak-business-automation-2400-if010 \n\n\n\nAny open source library may be included in one or more sub-components of IBM Cloud Pak for Business Automation. Open source updates are not always synchronized across all components."}],"title":"Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026."}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-11864","datePublished":"2026-09-15T17:30:12.589Z","dateReserved":"2026-06-10T11:56:00.828Z","dateUpdated":"2026-09-15T19:06:20.985Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-15 18:17:12","lastModifiedDate":"2026-09-16 19:24:58","problem_types":["CWE-643","CWE-643 CWE-643 Improper Neutralization of Data within XPath Expressions ('XPath Injection')"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-15T19:06:07.053018Z","id":"CVE-2026-11864","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"11864","Ordinal":"1","Title":"Multiple security vulnerabilities are addressed with IBM Cloud P","CVE":"CVE-2026-11864","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"11864","Ordinal":"1","NoteData":"IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.","Type":"Description","Title":"Multiple security vulnerabilities are addressed with IBM Cloud P"}]}}}