Executive brief
IBM App Connect Enterprise is an integration platform used to connect business applications and services. A vulnerability in the product allows a local attacker to trigger excessive recursion, causing the application to crash and become unavailable. This can disrupt critical business operations that depend on application integration.
Technical details
The vulnerability is an uncontrolled recursion flaw (CWE-674) in IBM App Connect Enterprise versions 12.0.1.0–12.0.12.28 and 13.0.1.0–13.0.8.1, as well as IBM Integration Bus for z/OS 10.1.0.0–10.1.0.7. A local attacker with limited privileges can trigger the recursion condition without user interaction, causing a denial of service by exhausting stack resources. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates local access and low privileges are required; the impact is high availability disruption. Patches are available: APAR IT49773 in App Connect Enterprise 13.0.8.2 and 12.0.12.29, and an interim fix for Integration Bus for z/OS 10.1.0.7.
Affected products
- IBM App Connect Enterprise 12.0.1.0 through 12.0.12.28, 13.0.1.0 through 13.0.8.1
- IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7
Timeline
- 2026-09-04: disclosed: CVE-2026-17440 published in NVD
- 2026-09-04: patched: APAR IT49773 released in App Connect Enterprise 13.0.8.2 and 12.0.12.29; interim fix available for Integration Bus for z/OS