CVE-2026-17156: IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multiple CVEs
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.
Other sources
IBM App Connect Enterprise could allow a local attacker to execute arbitrary code due to insecure deserialization.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 13.0.8.1Patch IT49855 - Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 12.0.12.28Patch IT49855
Event History
Frequently Asked Questions
Which App Connect Enterprise versions are affected?
Affected versions are 13.0.1.0 through 13.0.8.0 and 12.0.1.0 through 12.0.12.27.
What level of access does an attacker need?
Exploitation requires local access. The vector also indicates that no privileges are required, but user interaction is required.
What is the potential impact of successful exploitation?
A local attacker could execute arbitrary code. The supplied severity vector indicates high impact to confidentiality, integrity, and availability.