ZeroHour

CVE-2026-17416

Insecure Deserialization Allows Local Code Execution in IBM App Connect Enterprise

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

IBM App Connect Enterprise versions 13.0.1.0 through 13.0.8.0 and 12.0.1.0 through 12.0.12.27 contain an insecure deserialization flaw (CWE-502) that could allow a local attacker to execute arbitrary code on the affected system. Based on the CVSS vector (AV:L/PR:N/UI:R), exploitation requires local access to the host and some degree of user interaction, but no prior privileges. Successful exploitation gives the attacker code execution in the context of the product's runtime, with high impact on confidentiality, integrity, and availability (CVSS 7.8). Organizations running the affected 12.x or 13.x releases, typically as on-premises or containerized integration middleware, are exposed, though the local attack vector limits the risk to attackers who already have a foothold on or access to the server. There is no known public proof of concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported.

What to do: Upgrade App Connect Enterprise installations on 13.0.1.0-13.0.8.0 and 12.0.1.0-12.0.12.27 to a fixed version or interim fix per IBM's advisory as soon as one is available. Until patched, restrict local and shell access on hosts running ACE to trusted administrative accounts, and monitor those servers for unexpected processes or code execution in the ACE runtime context. Because the flaw requires a local foothold and user interaction, prioritize hosts that are multi-tenant or exposed to broader internal user access.

Affected
IBM App Connect Enterprise13.0.1.0 through 13.0.8.0
IBM App Connect Enterprise12.0.1.0 through 12.0.12.27
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.