Junglewise Threat Intelligence

CVE-2026-16180: IBM App Connect Enterprise XML entity expansion denial of service

CVE-2026-16180 · Severity: medium · CVSS 5.7 · Published 2026-09-04

Executive brief

IBM App Connect Enterprise is a middleware platform that integrates business applications and data flows. An authenticated user can crash the Toolkit component by submitting specially crafted XML with recursive entity definitions, causing a denial-of-service condition that disrupts integration work and message processing until the service is restarted.

Technical details

This vulnerability exists in the XML entity parsing logic of IBM App Connect Enterprise Toolkit and IBM Integration Bus for z/OS, stemming from improper validation of recursive XML entity references in Document Type Definitions (DTDs). The flaw allows an authenticated attacker with user interaction to submit a malicious XML document containing entity expansion attacks (CWE-776), causing excessive memory consumption or processing loops that crash the affected component. The vulnerability requires network access and valid authentication credentials to trigger, but no privilege elevation. Patches are available via Fix Pack releases 13.0.8.2 for version 13, 12.0.12.29 for version 12, and an interim fix for Integration Bus 10.1.0.7.

Affected products

  • IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, 12.0.1.0 through 12.0.12.28
  • IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7

Timeline

  • 2026-09-04: disclosed: Published in IBM Security Bulletin
  • 2026-09-04: patched: Fix Pack 13.0.8.2 for App Connect Enterprise v13, Fix Pack 12.0.12.29 for v12, interim fix available for Integration Bus 10.1.0.7

References

Related threats