CVE-2026-17133: IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multiple CVEs
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Other sources
IBM App Connect Enterprise could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 13.0.8.1Patch IT49855 - Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 12.0.12.28Patch IT49855
Event History
Frequently Asked Questions
Which deployments are affected?
Affected versions are IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0 and 12.0.1.0 through 12.0.12.27. The issue is identified in the App Connect Enterprise Toolkit.
Does exploitation require remote access or authentication?
The vector is local and privileges are not required according to the provided severity vector. Exploitation does require user interaction.
What could a successful attacker do?
A local attacker could execute arbitrary code by exploiting improper neutralization of special elements in an OS command. The severity vector indicates potential high impacts to confidentiality, integrity, and availability.