CVE-2026-17440: IBM App Connect Enterprise vulnerability
Published Sep 4, 2026
·Updated
IBM App Connect Enterprise could allow a local attacker to cause a denial of service due to uncontrolled recursion.
Affected Software
3 affected componentsFixes available
IBM App Connect Enterprise<=13.0.1.0 - 13.0.8.1
IBM App Connect Enterprise<=12.0.1.0 - 12.0.12.28
IBM Integration Bus for z/OS<=10.1.0.0 - 10.1.0.7
Event History
Sep 4, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as exploitable by a local attacker. The available information does not indicate remote exploitation.
2
Which IBM products are identified as affected?
IBM App Connect Enterprise and IBM Integration Bus for z/OS are listed.