SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12751

MEDIUM · CVSS 5.4 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM Cloud Pak for Business Automation is susceptible to HTML injection, allowing remote attackers to inject malicious HTML code. This vulnerability can lead to the execution of the injected code in the victim's web browser, potentially compromising user data and session integrity. Organizations utilizing this platform should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-12751
Severity
MEDIUM
CVSS
5.4
EPSS
0.27%

Original NVD Description

IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.