EIP-2026-119380
PRE-CVEIBM Business Process Manager - User Account Reconfiguration
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119380. PoCs published by 0in.
AI-analyzed exploit summary The exploit demonstrates a privilege escalation and information disclosure vulnerability in IBM BPM by allowing an authenticated but non-privileged user to modify administrator account preferences via the `setPreference` action. It includes steps to enumerate users and manipulate email or LDAP attributes to hijack notifications or reset passwords.
Description
IBM Business Process Manager - User Account Reconfiguration
Exploits (1)
The exploit demonstrates a privilege escalation and information disclosure vulnerability in IBM BPM by allowing an authenticated but non-privileged user to modify administrator account preferences via the `setPreference` action. It includes steps to enumerate users and manipulate email or LDAP attributes to hijack notifications or reset passwords.