CVE-2026-5515: IBM App Connect Enterprise is vulnerable to a confidential disclosure
Published May 7, 2026
·Updated
IBM App Connect Enterprise
Affected Software
2 affected componentsFixes available
IBM App Connect Enterprise<=13.0.1.0 - 13.0.7.0
IBM App Connect Enterprise>=13.0.1.0<13.0.7.1
Remediation
Information
IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise
Affected Product(s)Version(s)APARRemediation / FixesIBM App Connect Enterprise13.0.1.0 - 13.0.7.0IT49227
The APAR (IT49227) is available from
IBM App Connect Enterprise v13- Fix Pack Release 13.0.7.1 https://www.ibm.com/support/pages/download-ibm-app-connect-enterprise-13071
Event History
May 7, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
May 27, 2026
CVE Published
via MITRE·12:58 PM
Data Sourced
via MITRE·12:58 PM
RemedyDescriptionSeverity
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-5515?
The severity of CVE-2026-5515 is medium with a score of 5.5.
2
What type of vulnerability is CVE-2026-5515?
CVE-2026-5515 is a confidential disclosure vulnerability affecting IBM App Connect Enterprise.
3
How do I fix CVE-2026-5515?
To fix CVE-2026-5515, apply the appropriate fix from IBM for versions 13.0.1.0 to 13.0.7.0.
4
What could an attacker gain from CVE-2026-5515?
An attacker with local access may read potentially sensitive information stored in log files due to CVE-2026-5515.
5
Which versions of IBM App Connect Enterprise are affected by CVE-2026-5515?
IBM App Connect Enterprise versions 13.0.1.0 through 13.0.7.0 are affected by CVE-2026-5515.