CVE-2026-13449 HIGH

CVE-2026-13449: XXE attack in IBM Business Automation Manager Open Editions

Vendor Ibm
Product Business Automation Manager Open Editions
Weakness CWE-611 · XXE
Published June 30, 2026
Last update July 1, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

What the vulnerability does

01Description

IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

Key dates

02Disclosure timeline

June 30, 2026 CVE published
July 1, 2026 Record updated

Related vulnerabilities

04Related CVE