Junglewise Threat Intelligence

CVE-2026-3144: IBM API Connect use of default credentials

CVE-2026-3144 · Severity: high · CVSS 8.1 · Published 2026-07-08

Vendors: IBM.

Executive brief

IBM API Connect, a platform used for managing and securing web services (APIs), contains a security flaw where it uses default login credentials. An attacker could use these well-known credentials to gain unauthorized access to the system before a mandatory password change is enforced. This could lead to full control over the application, potentially exposing sensitive data or disrupting business operations.

Technical details

IBM API Connect is vulnerable to the use of default credentials (CWE-1392) in versions 12.1.0.0 through 12.1.0.3. An unauthenticated remote attacker can exploit this by logging into the application using factory-default settings before the system's initial setup process forces a credential update. Successful exploitation allows the attacker to gain unauthorized administrative access, potentially leading to a complete compromise of the application's confidentiality, integrity, and availability. The vulnerability is addressed in IBM API Connect version 12.1.1.0.

Affected products

  • IBM API Connect 12.1.0.0 - 12.1.0.3

Timeline

  • 2026-07-08: advisory
  • 2026-07-08: disclosed

References

Related threats