Description
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
Published: 2026-07-08
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM API Connect 12.1.0.0 and 12.1.0.3 contain hard‑coded administrative credentials that persist after installation until an explicit password change is performed. This weakness, identified as CWE‑1392, allows an attacker to authenticate as the administrator using known default credentials, granting full control over the API platform. With administrative access, an attacker can modify configuration, exfiltrate data, or disrupt services, compromising confidentiality, integrity, and availability of the system.

Affected Systems

All installations of IBM API Connect with the released versions 12.1.0.0 or 12.1.0.3 that have not yet updated the default administrator credentials are impacted. The vulnerability is triggered by hard‑coded admin username and password that remain unchanged until a mandated credential change occurs, exposing systems that have not applied any IBM maintenance update addressing this issue.

Risk and Exploitability

The CVSS score of 8.1 rates this vulnerability as high severity. Exploitation requires an attacker to obtain the default credentials and remotely connect to the administrative console; no special exploits are needed. The EPSS score of < 1% indicates a very low likelihood of exploitation in the current landscape, and the vulnerability is not listed in CISA KEV. The likely attack vector is inferred from the description to be remote access to the API Connect management console using the default credentials.

Generated by OpenCVE AI on August 12, 2026 at 01:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available IBM patch that removes hard‑coded credentials and disables the default authentication mechanism (CWE‑1392).
  • Immediately replace any remaining default administrator username and password with strong, unique credentials to prevent unauthorized access (CWE‑1392).
  • Restrict remote access to the API Connect administrative console by configuring firewall rules or IP whitelisting so that only trusted hosts or networks can reach the management interface (CWE‑1392).

Generated by OpenCVE AI on August 12, 2026 at 01:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
Title IBM API Connect Default Credentials
First Time appeared Ibm
Ibm api Connect
Weaknesses CWE-1392
CPEs cpe:2.3:a:ibm:api_connect:12.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:api_connect:12.1.0.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm api Connect
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-09T03:55:48.309Z

Reserved: 2026-02-24T19:53:12.296Z

Link: CVE-2026-3144

cve-icon Vulnrichment

Updated: 2026-07-08T17:38:07.891Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-08T16:16:28.463

Modified: 2026-07-10T17:01:12.167

Link: CVE-2026-3144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T01:45:04Z

Weaknesses