Description
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
Published: 2026-07-08
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM API Connect 12.1.0.0 through 12.1.0.3 includes hard‑coded administrative credentials that remain unchanged after installation until a mandatory password change is enforced. An attacker who discovers or guesses these default credentials can authenticate to the management console before any credential policy is applied, granting them unrestricted administrative access to the API platform.

Affected Systems

The vulnerability affects all installations of IBM API Connect releases 12.1.0.0, 12.1.0.1, 12.1.0.2, and 12.1.0.3. Systems running any of these versions that have not yet changed the default administrative username and password are exposed.

Risk and Exploitability

The CVSS score of 8.1 classifies this issue as high severity. Exploitation requires no special tools; an attacker simply needs the preset default credentials and remote connectivity to the administrative interface. The EPSS score of <1% indicates a very low probability of exploitation in the observed landscape, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote access to the API Connect management console using the default credentials.

Generated by OpenCVE AI on July 26, 2026 at 17:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Immediately change the default administrative username and password to a strong, unique value.
  • Limit network access to the API Connect administrative console by applying firewall rules, VPN restrictions, or IP whitelisting.
  • Apply any vendor‑issued patch or upgrade the product to a version that removes hard‑coded credentials.

Generated by OpenCVE AI on July 26, 2026 at 17:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
Title IBM API Connect Default Credentials
First Time appeared Ibm
Ibm api Connect
Weaknesses CWE-1392
CPEs cpe:2.3:a:ibm:api_connect:12.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:api_connect:12.1.0.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm api Connect
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-09T03:55:48.309Z

Reserved: 2026-02-24T19:53:12.296Z

Link: CVE-2026-3144

cve-icon Vulnrichment

Updated: 2026-07-08T17:38:07.891Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T17:45:17Z

Weaknesses