{"api_version":"1","generated_at":"2026-08-05T20:40:52+00:00","cve":"CVE-2026-12730","urls":{"html":"https://cve.report/CVE-2026-12730","api":"https://cve.report/api/cve/CVE-2026-12730.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-12730","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-12730"},"summary":{"title":"Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers","description":"IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-08-05 16:16:49","updated_at":"2026-08-05 19:17:20"},"problem_types":["CWE-297","CWE-297 CWE-297 Improper Validation of Certificate with Host Mismatch"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"3.8","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"3.8","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.8,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7282596","name":"https://www.ibm.com/support/pages/node/7282596","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-12730","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12730","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Business Automation Workflow containers and traditional","version":"affected 26.0.0","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Business Automation Workflow containers and traditional","version":"affected 25.0.0 25.0.0 Interim Fix 005 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Business Automation Workflow containers and traditional","version":"affected 24.0.1 24.0.1 Interim Fix 007 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Business Automation Workflow containers and traditional","version":"affected 24.0.0 24.0.0 Interim Fix 009 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerability now by upgrading.\n\nAffected Product(s)Version(s)Remediation / FixIBM Business Automation Workflow containersV26.0.0Apply container  26.0.0-IF001 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-26000-interim-fixes IBM Business Automation Workflow traditionalV26.0.0Apply traditional  26.0.0-IF001 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-26000-interim-fixes IBM Business Automation Workflow containersV25.0.0 - V25.0.0-IF005Apply container  25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-25000-interim-fixes IBM Business Automation Workflow traditionalV25.0.0 - V25.0.0-IF005Apply traditional  25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-25000-interim-fixes IBM Business Automation Workflow containersV24.0.1 - V24.0.1-IF007Apply container  24.0.1-IF008 https://www.ibm.com/support/pages/node/7183042 IBM Business Automation Workflow traditionalV24.0.1 - V24.0.1-IF007Apply traditional  24.0.1-IF008 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24010-interim-fixes IBM Business Automation Workflow containersV24.0.0 - V24.0.0-IF009Apply container  24.0.0-IF010 https://www.ibm.com/support/pages/node/7159792 IBM Business Automation Workflow traditionalV24.0.0 - V24.0.0-IF009Apply traditional  24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24000-interim-fixes","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-12730","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-05T17:59:02.663931Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-05T17:59:18.166Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:26.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:25.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:25.0.0:interim_fix_005:*:*:*:*:*:*","cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.1:interim_fix_007:*:*:*:*:*:*","cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.0:interim_fix_009:*:*:*:*:*:*"],"product":"Business Automation Workflow containers and traditional","vendor":"IBM","versions":[{"status":"affected","version":"26.0.0"},{"lessThanOrEqual":"25.0.0 Interim Fix 005","status":"affected","version":"25.0.0","versionType":"semver"},{"lessThanOrEqual":"24.0.1 Interim Fix 007","status":"affected","version":"24.0.1","versionType":"semver"},{"lessThanOrEqual":"24.0.0 Interim Fix 009","status":"affected","version":"24.0.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.</p>"}],"value":"IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.8,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-297","description":"CWE-297 Improper Validation of Certificate with Host Mismatch","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-05T17:25:51.335Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7282596"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM strongly recommends addressing the vulnerability now by upgrading.</p><div><table><thead><tr><th>Affected Product(s)</th><th>Version(s)</th><th>Remediation / Fix</th></tr></thead><tbody><tr><td>IBM Business Automation Workflow containers</td><td>V26.0.0</td><td>Apply container <a href=\"https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-26000-interim-fixes\" rel=\"nofollow\">26.0.0-IF001</a></td></tr><tr><td>IBM Business Automation Workflow traditional</td><td>V26.0.0</td><td>Apply traditional <a href=\"https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-26000-interim-fixes\" rel=\"nofollow\">26.0.0-IF001</a></td></tr><tr><td>IBM Business Automation Workflow containers</td><td>V25.0.0 - V25.0.0-IF005</td><td>Apply container <a href=\"https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-25000-interim-fixes\" rel=\"nofollow\">25.0.0-IF006</a></td></tr><tr><td>IBM Business Automation Workflow traditional</td><td>V25.0.0 - V25.0.0-IF005</td><td>Apply traditional <a href=\"https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-25000-interim-fixes\" rel=\"nofollow\">25.0.0-IF006</a></td></tr><tr><td>IBM Business Automation Workflow containers</td><td>V24.0.1 - V24.0.1-IF007</td><td>Apply container <a href=\"https://www.ibm.com/support/pages/node/7183042\" rel=\"nofollow\">24.0.1-IF008</a></td></tr><tr><td>IBM Business Automation Workflow traditional</td><td>V24.0.1 - V24.0.1-IF007</td><td>Apply traditional <a href=\"https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24010-interim-fixes\" rel=\"nofollow\">24.0.1-IF008</a></td></tr><tr><td>IBM Business Automation Workflow containers</td><td>V24.0.0 - V24.0.0-IF009</td><td>Apply container <a href=\"https://www.ibm.com/support/pages/node/7159792\" rel=\"nofollow\">24.0.0-IF010</a></td></tr><tr><td>IBM Business Automation Workflow traditional</td><td>V24.0.0 - V24.0.0-IF009</td><td>Apply traditional <a href=\"https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24000-interim-fixes\" rel=\"nofollow\">24.0.0-IF010</a></td></tr></tbody></table></div>"}],"value":"IBM strongly recommends addressing the vulnerability now by upgrading.\n\nAffected Product(s)Version(s)Remediation / FixIBM Business Automation Workflow containersV26.0.0Apply container  26.0.0-IF001 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-26000-interim-fixes IBM Business Automation Workflow traditionalV26.0.0Apply traditional  26.0.0-IF001 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-26000-interim-fixes IBM Business Automation Workflow containersV25.0.0 - V25.0.0-IF005Apply container  25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-25000-interim-fixes IBM Business Automation Workflow traditionalV25.0.0 - V25.0.0-IF005Apply traditional  25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-25000-interim-fixes IBM Business Automation Workflow containersV24.0.1 - V24.0.1-IF007Apply container  24.0.1-IF008 https://www.ibm.com/support/pages/node/7183042 IBM Business Automation Workflow traditionalV24.0.1 - V24.0.1-IF007Apply traditional  24.0.1-IF008 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24010-interim-fixes IBM Business Automation Workflow containersV24.0.0 - V24.0.0-IF009Apply container  24.0.0-IF010 https://www.ibm.com/support/pages/node/7159792 IBM Business Automation Workflow traditionalV24.0.0 - V24.0.0-IF009Apply traditional  24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24000-interim-fixes"}],"title":"Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers"}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-12730","datePublished":"2026-08-05T15:57:37.007Z","dateReserved":"2026-06-19T15:59:20.718Z","dateUpdated":"2026-08-05T17:59:18.166Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-05 16:16:49","lastModifiedDate":"2026-08-05 19:17:20","problem_types":["CWE-297","CWE-297 CWE-297 Improper Validation of Certificate with Host Mismatch"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","baseScore":3.8,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-05T17:59:02.663931Z","id":"CVE-2026-12730","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"12730","Ordinal":"1","Title":"Improper Validation of Certificate with Host Mismatch in IBM Bus","CVE":"CVE-2026-12730","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"12730","Ordinal":"1","NoteData":"IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.","Type":"Description","Title":"Improper Validation of Certificate with Host Mismatch in IBM Bus"}]}}}