CVE-2026-17416
—Insecure Deserialization Allows Local Code Execution in IBM App Connect Enterprise
IBM App Connect Enterprise versions 13.0.1.0 through 13.0.8.0 and 12.0.1.0 through 12.0.12.27 contain an insecure deserialization flaw (CWE-502) that could allow a local attacker to execute arbitrary code on the affected system. Based on the CVSS vector (AV:L/PR:N/UI:R), exploitation requires local access to the host and some degree of user interaction, but no prior privileges. Successful exploitation gives the attacker code execution in the context of the product's runtime, with high impact on confidentiality, integrity, and availability (CVSS 7.8). Organizations running the affected 12.x or 13.x releases, typically as on-premises or containerized integration middleware, are exposed, though the local attack vector limits the risk to attackers who already have a foothold on or access to the server. There is no known public proof of concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported.
What to do: Upgrade App Connect Enterprise installations on 13.0.1.0-13.0.8.0 and 12.0.1.0-12.0.12.27 to a fixed version or interim fix per IBM's advisory as soon as one is available. Until patched, restrict local and shell access on hosts running ACE to trusted administrative accounts, and monitor those servers for unexpected processes or code execution in the ACE runtime context. Because the flaw requires a local foothold and user interaction, prioritize hosts that are multi-tenant or exposed to broader internal user access.
| IBM App Connect Enterprise | 13.0.1.0 through 13.0.8.0 |
| IBM App Connect Enterprise | 12.0.1.0 through 12.0.12.27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.