IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1
IBM App Connect Enterprise has a flaw that can let an authenticated remote user bypass security restrictions. This could enable higher privileges or disrupt the service.
- Severity
- HighCVSS 3.1 · 8.8
- Fix
- Not confirmedLast checked today
- Affected versions
- 13.0.1.0 through 13.0.8.1; 12.0.1.0 through 12.0.12.27
- Weakness
- CWE-863Incorrect Authorization
- Exploit likelihood
- 0.37% in 30 daysEPSS, higher than 30% of known flaws
- Affects
- App Connect Enterprise
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: no · Technical impact: total
- EU ID
- EUVD-2026-75803ENISA vulnerability database
How it works
- An attacker must first have a valid account that can reach App Connect Enterprise remotely.
- The runtime can make the wrong authorization decision for a request.
- That can let the account bypass security restrictions.
- IBM identifies privilege escalation and denial of service as potential results.
What to do
Check the installed App Connect Enterprise version against IBM's security bulletin. Versions 13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.27 are affected.
Apply IBM App Connect Enterprise v13 Fix Pack Release 13.0.8.2 for version 13, or v12 Fix Pack Release 12.0.12.28 for version 12, as listed in IBM's security bulletin.
Technical details
CVE-2026-75624 is an incorrect-authorization issue with a CVSS score of 8.8. IBM lists privilege escalation and denial of service as potential impacts. The attacker needs low-level authenticated access and no user interaction.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- ibm.com · 7286532 vendor-advisory patch NVD
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-75624 third party advisory vdb entry
- cvefeed.io · CVE-2026-75624 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-75624