Junglewise Threat Intelligence

CVE-2026-9074: IBM API Connect SQL injection in password reset functionality

CVE-2026-9074 · Severity: critical · CVSS 9.1 · Published 2026-07-08

Vendors: IBM.

Executive brief

IBM API Connect, a platform used for managing and securing APIs, contains a critical vulnerability in its password reset feature. An unauthorized attacker could exploit this flaw to gain access to sensitive data or modify system information without needing a valid account. This could lead to a full compromise of the API management platform and the data it protects.

Technical details

IBM API Connect is vulnerable to an unauthenticated SQL injection (CWE-89) within its password reset component. The vulnerability stems from improper neutralization of special elements in SQL commands, allowing a remote attacker to send specially crafted requests to the application. Successful exploitation does not require authentication or user interaction and can result in the unauthorized disclosure or modification of sensitive information stored in the back-end database. IBM has addressed this vulnerability in versions 10.0.8.10 and 12.1.1.0.

Affected products

  • IBM API Connect 10.0.8.0 - 10.0.8.9, 12.1.0.0 - 12.1.0.3

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory

References

Related threats