CVE-2026-17156
moderateInsecure Deserialization in IBM App Connect Enterprise 12/13 Enables Local Code Execution
IBM App Connect Enterprise contains an insecure deserialization flaw (CWE-502) that could allow a local attacker to execute arbitrary code on the server running the integration runtime. Exploitation requires local access to the host and some degree of user interaction, such as tricking an authorized user or administrator into processing attacker-controlled data, but requires no privileges. Successful exploitation gives the attacker code execution with high impact to confidentiality, integrity, and availability of the integration node and the data flows it handles (CVSS 3.1: 7.8). Affected deployments are App Connect Enterprise 13.0.1.0–13.0.8.0 and 12.0.1.0–12.0.12.27, whether installed on-premises or in containerized form. The CVE is not in CISA's KEV catalog, no public proof of concept is known, and there are no reports of exploitation in the wild.
What to do: Apply IBM's fix for CVE-2026-17156 by upgrading App Connect Enterprise 12.0.x deployments past 12.0.12.27 and 13.0.x deployments past 13.0.8.0, following the interim fixes or fix packs in IBM's official advisory. Until patched, restrict local and interactive access to ACE hosts, run integration nodes under a least-privileged service account, and audit for unexpected processes spawned by the ACE runtime. Because exploitation requires local access plus user interaction, prioritize servers shared by multiple users or developers.
| IBM App Connect Enterprise | 13.0.1.0 through 13.0.8.0 |
| IBM App Connect Enterprise | 12.0.1.0 through 12.0.12.27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.