Executive brief
IBM App Connect Enterprise is an integration and messaging platform used to connect applications and services across enterprises. A vulnerability allows authenticated users to bypass security restrictions and gain unauthorized elevated privileges or cause service disruptions, potentially compromising the integrity and availability of critical business integrations.
Technical details
The vulnerability is an incorrect authorization flaw (CWE-863) in IBM App Connect Enterprise that allows authenticated remote attackers to bypass security restrictions. The issue affects the runtime environment and permits attackers with valid credentials to escalate privileges beyond their authorization level. The vulnerability is exploitable over the network without user interaction, with only low privilege requirements (authenticated user). Fixes are available through Fix Pack Release 13.0.8.2 (APAR IT49854) for version 13.x and 12.0.12.28 for version 12.x.
Affected products
- IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, 12.0.1.0 through 12.0.12.27
Timeline
- 2026-09-07: disclosed: IBM Security Bulletin published
- 2026-09-10: advisory: Entered NVD database