Description
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
Published: 2026-07-30
Score: 8.8 High
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM App Connect Enterprise is vulnerable to a command injection flaw caused by improper neutralization of CRLF characters. When a remote attacker sends a crafted request containing CRLF sequences to the configuration interface, the system misinterprets the input as part of a command line and executes it. This flaw permits the attacker to run arbitrary commands on the host, potentially leading to full system compromise and the ability to compromise other components in the environment.

Affected Systems

IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.7.2 are affected. These releases are vulnerable if the exposed configuration interface is reachable by an attacker.

Risk and Exploitability

The CVSS score of 8.8 reflects the high impact of remote code execution with user authentication not required for the exploitation vector. The EPSS score is less than 1%, indicating a very low but nonzero probability of exploitation in the current landscape, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only network access to the configuration interface; no complex preconditions are documented, so the risk is considered high for any exposed systems.

Generated by OpenCVE AI on August 2, 2026 at 05:20 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise Affected Product(s)Version(s)APARRemediation / FixesIBM App Connect Enterprise13.0.1.0 - 13.0.7.2IT49745 The APAR (IT49745) is available from IBM App Connect Enterprise v13- Fix Pack Release 13.0.8.0 https://www.ibm.com/support/pages/download-ibm-app-connect-enterprise-13080 IBM App Connect Enterprise12.0.1.0 - 12.0.12.27IT49745 The APAR (IT49745) is available from IBM App Connect Enterprise v12- Fix Pack Release 12.0.12.28 https://www.ibm.com/support/pages/download-ibm-app-connect-enterprise-1201228-fix-pack


OpenCVE Recommended Actions

  • Apply the IBM App Connect 13.0.8.0 fix pack for the 13.x branch or the 12.0.12.28 fix pack for the 12.x branch, which contain the CRLF neutralization fix.
  • Configure the application to disable or restrict the exposed configuration interface if it is not required for normal operations, limiting the attack surface.
  • Ensure that any input accepted by the configuration interface is properly sanitized and that CRLF characters are not interpreted as command separators; review custom configuration scripts for recent changes.

Generated by OpenCVE AI on August 2, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
Title IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings
First Time appeared Ibm
Ibm app Connect Enterprise
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.27:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.7.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm app Connect Enterprise
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm App Connect Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-31T03:56:01.243Z

Reserved: 2026-07-02T19:52:00.961Z

Link: CVE-2026-14522

cve-icon Vulnrichment

Updated: 2026-07-30T15:15:53.197Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T15:16:25.693

Modified: 2026-08-05T14:39:44.343

Link: CVE-2026-14522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:30:06Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')