---
id: CVE-2026-11864
title: >-
  IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001,
  25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008,
  and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection
  vuln…
summary: >-
  IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001,
  25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008,
  and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection
  vuln…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-643
vendor: IBM
product: Cloud Pak for Business Automation
affected:
  - cloud_pak_for_business_automation >= 26.0.0 <= 26.0.0 Interim Fix 001
  - cloud_pak_for_business_automation >= 25.0.0 <= 25.0.0 Interim Fix 005
  - cloud_pak_for_business_automation >= 24.0.1 <= 24.0.1 Interim Fix 008
  - cloud_pak_for_business_automation >= 24.0.0 <= 24.0.0 Interim Fix 009
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:24:58.293'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11864'
references:
  - url: 'https://www.ibm.com/support/pages/node/7285931'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T19:06:07.053018Z'
ingestedAt: '2026-09-15T17:41:02.936Z'
epss: 0.00219
epssPercentile: 0.10983
---

## Overview

IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive application data and/or determine the structure of the XML document.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
