{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aibmbusiness_automation_workflow/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-13107"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Business Automation Workflow"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xxe","ibm"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Business Automation Workflow (BAW) is affected by a vulnerability identified as CVE-2026-13107, involving the use of default programming model artifacts that are susceptible to XML External Entity (XXE) injection. The vulnerability exists within both containerized and traditional deployments of the platform. XXE occurs when an XML parser is configured to process external entities defined in a Document Type Definition (DTD) without proper validation or restriction. If an attacker can supply malicious XML input to the application, they may be able to force the parser to disclose sensitive local files, interact with internal services via Server-Side Request Forgery (SSRF), or cause a denial of service. The impact of this vulnerability is significant, given the role of BAW in enterprise process management and data integration. Organizations utilizing IBM BAW should review their XML parsing configurations and apply available security updates from IBM to mitigate potential exploitation of this flaw.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-13107 allows an attacker to perform unauthorized file disclosure and potentially facilitate server-side request forgery (SSRF). This could lead to the compromise of sensitive internal data or lateral movement within the environment where BAW is deployed, impacting organizations that rely on the platform for critical workflow and process automation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of IBM Business Automation Workflow in the environment and review current versioning against IBM security advisories for CVE-2026-13107.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation for any XML-based interfaces or API endpoints that interface with BAW.\u003c/li\u003e\n\u003cli\u003eDisable support for external entities and DTD processing within the XML parser configuration of the BAW environment if a patch cannot be immediately applied.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for XML payloads containing unusual entity references or external system requests.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T23:36:36Z","date_published":"2026-09-14T21:35:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-13107/","summary":"IBM Business Automation Workflow contains a vulnerability in default programming artifacts that allows for XML External Entity (XXE) injection attacks, potentially enabling unauthorized file access or server-side request forgery.","title":"XML External Entity Injection in IBM Business Automation Workflow","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-13107/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ibm:business_automation_workflow:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}