CVE-2023-38734: IBM Robotic Process Automation

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481.

Affected products

  • IBM Robotic Process Automation: from 21.0.0, up to and including 21.0.7.1; version 23.0.0 only; version 23.0.1 only

Published 2023-08-22. Last modified 2026-06-17.