Junglewise Threat Intelligence

CVE-2026-81832: IBM App Connect Enterprise SAP Adapter XXE injection

CVE-2026-81832 · Severity: high · CVSS 7.7 · Published 2026-09-04

Technologies: IBM Integration Bus for z/OS, IBM App Connect Enterprise. Vendors: IBM.

Executive brief

IBM App Connect Enterprise's SAP Adapter is vulnerable to XML external entity (XXE) injection attacks, allowing authenticated remote attackers to read sensitive files and data from systems running affected versions. This vulnerability could expose confidential business data, configuration files, and system credentials to attackers with network access to the integration platform.

Technical details

CVE-2026-81832 is an XXE (XML External Entity) injection vulnerability in the SAP Adapter component of IBM App Connect Enterprise and IBM Integration Bus for z/OS. The vulnerability exists in the SAP Adapter's XML parsing logic, which fails to properly restrict or validate external entity references when processing XML input (CWE-611). An authenticated remote attacker can exploit this by submitting crafted XML payloads to the adapter, allowing arbitrary file read access and potential information disclosure across system boundaries. The vulnerability requires valid authentication credentials and network access to the affected integration platform. Fixes are available in App Connect Enterprise v13.0.8.2 and v12.0.12.29 via APAR IT49773, and an interim fix is available for Integration Bus for z/OS 10.1.0.7.

Affected products

  • IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, 12.0.1.0 through 12.0.12.28
  • IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7

Timeline

  • 2026-09-04: disclosed
  • 2026-09: patched: Fix pack 13.0.8.2 and 12.0.12.29 available; interim fix for 10.1.0.7

References

Related threats