CVE-2026-14522: IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
Other sources
IBM App Connect Enterprise could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 12.0.12.28Patch IT49745 - Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 13.0.8.0Patch IT49745
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14522?
The severity of CVE-2026-14522 is rated high with a score of 8.8.
What vulnerabilities are associated with CVE-2026-14522?
CVE-2026-14522 is associated with arbitrary file read and arbitrary changes to configuration settings in IBM App Connect Enterprise.
How do I fix CVE-2026-14522?
To fix CVE-2026-14522, upgrade to the latest patched version of IBM App Connect Enterprise as recommended by IBM.
Who is affected by CVE-2026-14522?
IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.2 and 12.0.1.0 through 12.0.12.27 are affected by CVE-2026-14522.
What types of attacks does CVE-2026-14522 allow?
CVE-2026-14522 allows remote attackers to execute arbitrary commands due to improper handling of CRLF characters.