CVE-2026-75624: IBM App Connect Enterprise is vulnerable to privilege escalation and Denial of Service
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.
Other sources
IBM App Connect Enterprise could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 12.0.12.28Patch IT49854 - Upgrade
Upgrade
IBM App Connect Enterpriseto a version that resolves this vulnerability.Fixed in 13.0.8.2Patch IT49854
Event History
Frequently Asked Questions
Which deployments are affected?
IBM App Connect Enterprise versions 13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.27 are affected.
Does exploitation require prior access?
Yes. The issue requires a remote attacker to be authenticated and have low-level privileges; no user interaction is required.
What could a successful attacker do?
An authenticated attacker could bypass security restrictions, leading to privilege escalation and potentially high impact to confidentiality, integrity, and availability.