ZeroHour

CVE-2026-17133

Local OS Command Injection in IBM App Connect Enterprise 12.x/13.x

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

IBM App Connect Enterprise contains an OS command injection flaw (CWE-78), caused by improper neutralization of special elements passed to an operating-system command, that could allow a local attacker to execute arbitrary code on the affected host. Exploitation occurs from the local attack surface and, per the CVSS vector, requires no privileges but does require user interaction — meaning a victim on the same machine would need to be tricked into opening or interacting with a malicious element (e.g., a crafted file or project). Successful exploitation yields arbitrary code execution with high impact to confidentiality, integrity, and availability on the server running the integration runtime. Affected deployments are ACE 13.0.1.0–13.0.8.0 and 12.0.1.0–12.0.12.27, typically enterprise integration servers in data centers. The vulnerability is scored 7.8 (high), but it is not in the CISA KEV catalog and no public proof of concept or in-the-wild exploitation is known.

What to do: Apply IBM's fixed builds as described in the official advisory — move 13.0.x deployments beyond 13.0.8.0 and 12.0.x deployments beyond 12.0.12.27 via the latest fix pack or interim fix. Because the attack is local and requires user interaction, restrict interactive local and RDP/SSH access on ACE servers to trusted administrative accounts, and train operators not to open untrusted message flows, projects, or files on integration hosts. Review local audit logs for unexpected command or process execution under the ACE service account on systems running the affected versions.

Affected
IBM App Connect Enterprise13.0.1.0 through 13.0.8.0
IBM App Connect Enterprise12.0.1.0 through 12.0.12.27
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Weakness
CWE-78
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.