Junglewise Threat Intelligence

CVE-2026-78543: IBM App Connect Enterprise infinite loop denial of service

CVE-2026-78543 · Severity: medium · CVSS 5.3 · Published 2026-09-04

Technologies: IBM Integration Bus for z/OS, IBM App Connect Enterprise. Vendors: IBM.

Executive brief

IBM App Connect Enterprise is a middleware platform that connects various business applications and systems. A remote attacker can exploit an infinite loop condition to crash or freeze the service, causing applications connected through it to become unavailable until the service is restarted. This could disrupt critical business operations that depend on integration flows.

Technical details

The vulnerability is an infinite loop (CWE-835) in IBM App Connect Enterprise that allows a remote unauthenticated attacker to trigger a denial of service condition. The infinite loop is reachable over the network with no authentication required, causing the integration server to consume CPU and become unresponsive. An attacker can craft a specific input or message that causes the application to enter an unreachable exit condition loop, effectively denying service to legitimate users. Patches are available via APAR IT49773 in fix pack 13.0.8.2 for version 13.x and 12.0.12.29 for version 12.x.

Affected products

  • IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, 12.0.1.0 through 12.0.12.28
  • IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7

Timeline

  • 2026-09-04: disclosed: CVE-2026-78543 published by IBM
  • 2026-09-04: patched: Fix pack 13.0.8.2 and 12.0.12.29 available via APAR IT49773

References

Related threats