Junglewise Threat Intelligence

CVE-2026-17444: IBM App Connect Enterprise XXE injection in adapter nodes

CVE-2026-17444 · Severity: medium · CVSS 5.3 · Published 2026-09-04

Executive brief

IBM App Connect Enterprise is middleware software that connects applications and data across an organization. A vulnerability in its adapter nodes allows authenticated attackers to extract sensitive information through XML external entity (XXE) injection attacks, potentially exposing confidential business data and credentials stored in backend systems.

Technical details

CVE-2026-17444 is an XML external entity (XXE) injection vulnerability (CWE-611) in IBM App Connect Enterprise adapter nodes that fails to properly restrict XML external entity references. An authenticated network attacker can exploit this by submitting specially crafted XML payloads to trigger XXE expansion, allowing them to read arbitrary files or access sensitive information from the server. The vulnerability requires authentication and accepts input via HTTP with high attack complexity. Patches are available via APAR IT49773 in Fix Pack releases 13.0.8.2 (for v13) and 12.0.12.29 (for v12), with an interim fix for Integration Bus for z/OS 10.1.0.7.

Affected products

  • IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, 12.0.1.0 through 12.0.12.28
  • IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7

Timeline

  • 2026-09-04: disclosed: Public disclosure via NVD and IBM Security Bulletin
  • 2026-09-04: patched: Fix Pack 13.0.8.2 and 12.0.12.29 available; interim fix for z/OS 10.1.0.7

References

Related threats