CVE-2025-36091: IBM Cloud Pak For Business Automation

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.

Affected products

  • IBM Cloud Pak For Business Automation: version 24.0.0 only; version 24.0.1 only; version 25.0.0 only

Published 2025-11-03. Last modified 2026-06-17.