Description
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

IBM App Connect Enterprise is vulnerable to a privilege escalation flaw that allows a remote authenticated attacker to bypass security restrictions. The weakness corresponds to a broken authorization control and can lead to unauthorized access to sensitive data or functions as CWE‑863 and is characterized by incorrect enforcement of user permissions.

Affected Systems

The vulnerability affects IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.8.1. Users of these releases should apply the APAR IT49854 fix, which is available in the 12.0.12.28 and 13.0.8.2 fix packs.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity for authenticated attackers who can elevate privileges. No EPSS score is provided, and the issue is not listed in the CISA KEV catalog, suggesting limited evidence of active exploitation. However, because authorization is required, the attack vector is considered remote authenticated; attackers must first obtain valid credentials to exploit the flaw. While not a zero‑day, the high impact warrants prompt remediation.

Generated by OpenCVE AI on September 11, 2026 at 03:58 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise Affected Product(s)Version(s)APARRemediation / FixesIBM App Connect Enterprise13.0.1.0 - 13.0.8.1IT49854 The APAR (IT49854) is available from IBM App Connect Enterprise v13- Fix Pack Release 13.0.8.2 https://www.ibm.com/support/pages/download-ibm-app-connect-enterprise-13082 IBM App Connect Enterprise12.0.1.0 - 12.0.12.27IT49854 The APAR (IT49854) is available from IBM App Connect Enterprise v12- Fix Pack Release 12.0.12.28 https://www.ibm.com/support/pages/download-ibm-app-connect-enterprise-1201228-fix-pack


OpenCVE Recommended Actions

  • Apply the IBM App Connect Enterprise fix pack 13.0.8.2 (or 12.0.12.28) to address the APAR IT49854 vulnerability.
  • Restrict privileged user accounts to the minimum necessary permissions and review authorization policies for the application.
  • Deploy monitoring to detect and block attempts to bypass authorization controls, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on September 11, 2026 at 03:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.
Title IBM App Connect Enterprise is vulnerable to privilege escalation and Denial of Service
First Time appeared Ibm
Ibm app Connect Enterprise
Weaknesses CWE-863
CPEs cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.27:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:app_connect_enterprise:13.0.8.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm app Connect Enterprise
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm App Connect Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:45:42.449Z

Reserved: 2026-08-18T01:00:24.786Z

Link: CVE-2026-75624

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T22:16:59.313

Modified: 2026-09-11T14:56:50.613

Link: CVE-2026-75624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:45:06Z

Weaknesses