CVE-2026-15435: IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
Other sources
IBM App Connect Enterprise could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterprise 13.0.1.0 - 13.0.7.2to a version that resolves this vulnerability.Fixed in 13.0.8.0Patch IT49737 - Upgrade
Upgrade
IBM App Connect Enterprise 12.0.1.0 - 12.0.12.27to a version that resolves this vulnerability.Fixed in 12.0.12.28Patch IT49737
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15435?
The severity of CVE-2026-15435 is rated as critical with a score of 9.8.
What vulnerabilities does CVE-2026-15435 exploit?
CVE-2026-15435 exploits a path traversal vulnerability that allows arbitrary file write through directory traversal techniques.
How do I fix CVE-2026-15435?
To fix CVE-2026-15435, upgrade IBM App Connect Enterprise to version 13.0.7.3 or 12.0.12.28 or later.
Which versions of IBM App Connect Enterprise are affected by CVE-2026-15435?
IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.2 and 12.0.1.0 through 12.0.12.27 are affected by CVE-2026-15435.
What types of attacks can CVE-2026-15435 enable?
CVE-2026-15435 can enable remote attackers to write arbitrary files on the system via specially crafted URL requests.