ZeroHour

CVE-2026-17156

moderate

Insecure Deserialization in IBM App Connect Enterprise 12/13 Enables Local Code Execution

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

IBM App Connect Enterprise contains an insecure deserialization flaw (CWE-502) that could allow a local attacker to execute arbitrary code on the server running the integration runtime. Exploitation requires local access to the host and some degree of user interaction, such as tricking an authorized user or administrator into processing attacker-controlled data, but requires no privileges. Successful exploitation gives the attacker code execution with high impact to confidentiality, integrity, and availability of the integration node and the data flows it handles (CVSS 3.1: 7.8). Affected deployments are App Connect Enterprise 13.0.1.0–13.0.8.0 and 12.0.1.0–12.0.12.27, whether installed on-premises or in containerized form. The CVE is not in CISA's KEV catalog, no public proof of concept is known, and there are no reports of exploitation in the wild.

What to do: Apply IBM's fix for CVE-2026-17156 by upgrading App Connect Enterprise 12.0.x deployments past 12.0.12.27 and 13.0.x deployments past 13.0.8.0, following the interim fixes or fix packs in IBM's official advisory. Until patched, restrict local and interactive access to ACE hosts, run integration nodes under a least-privileged service account, and audit for unexpected processes spawned by the ACE runtime. Because exploitation requires local access plus user interaction, prioritize servers shared by multiple users or developers.

Affected
IBM App Connect Enterprise13.0.1.0 through 13.0.8.0
IBM App Connect Enterprise12.0.1.0 through 12.0.12.27
Estimated exposure
moderatelikely thousands to low tens of thousands of enterprise deployments (order of magnitude: ~10^3–10^4 systems) — App Connect Enterprise is licensed enterprise middleware with no public install telemetry; the estimate is based on typical deployment patterns for IBM integration products at mid-size and large organizations, and because the attack vector…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.