CVE-2026-3207: TIBCO Bpm Enterprise

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.

Affected products

  • TIBCO Bpm Enterprise: from 4.3.0, before 4.3.5 (fixed in 4.3.5)

Published 2026-03-17. Last modified 2026-06-17.