Executive brief
IBM App Connect Enterprise is an integration platform that connects business applications and data across an organization. A local attacker can execute arbitrary code on systems running affected versions (12.0.1.0–12.0.12.27 and 13.0.1.0–13.0.8.0) by exploiting insecure deserialization, potentially compromising the entire integration infrastructure and any connected systems.
Technical details
The vulnerability is a CWE-502 insecure deserialization flaw (CVE-2026-17416) in IBM App Connect Enterprise that allows arbitrary code execution. The attack vector is local (AV:L) with no privileges required (PR:N), but requires user interaction (UI:R). An attacker can craft malicious serialized objects that, when deserialized by the application, execute arbitrary code with the privileges of the process. Patches are available: version 13.0.8.1 and 12.0.12.28 include APAR IT49855.
Affected products
- IBM App Connect Enterprise 12.0.1.0–12.0.12.27, 13.0.1.0–13.0.8.0
Timeline
- 2026-09-07: disclosed
- 2026-09-14: advisory