Junglewise Threat Intelligence

CVE-2026-16689: IBM App Connect Enterprise improper logging of credentials

CVE-2026-16689 · Severity: medium · CVSS 6.2 · Published 2026-09-04

Executive brief

IBM App Connect Enterprise is a middleware platform that integrates enterprise applications and systems. A vulnerability allows local attackers to read sensitive authentication credentials from application logs in cleartext, potentially enabling unauthorized access to backend systems and data.

Technical details

The vulnerability exists in IBM App Connect Enterprise's logging mechanism, where credentials are written to log files without proper sanitization or encryption (CWE-532: Insertion of Sensitive Information into Log File). An unauthenticated local attacker can access these logs to obtain sensitive information. The attack vector is local with no privileges required, meaning any user with access to the system's filesystem can exploit this. The fix is available through APAR IT49773, packaged in Enterprise v13 Fix Pack 13.0.8.2 and v12 Fix Pack 12.0.12.29 for App Connect Enterprise, and as an interim fix for Integration Bus for z/OS 10.1.0.7.

Affected products

  • IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28
  • IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7

Timeline

  • 2026-09-04: disclosed: Security bulletin published by IBM
  • 2026-09-04: patched: Fix available through APAR IT49773 (v13.0.8.2, v12.0.12.29, and interim fix for z/OS)

References

Related threats