ZeroHour

CVE-2026-75624

moderate

Incorrect authorization security bypass in IBM App Connect Enterprise

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM App Connect Enterprise, an enterprise integration and messaging middleware product, is affected by an incorrect authorization flaw (CWE-863) in versions 13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.27. The issue can be triggered remotely by any authenticated user who sends a request to functionality where the product fails to correctly enforce its authorization checks, with no user interaction or special conditions required (CVSS AV:N/AC:L/PR:L/UI:N). An attacker who successfully exploits it can bypass security restrictions and gain unauthorized access to protected operations and data, with IBM scoring the potential impact as high on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). All customers running the affected version ranges of App Connect Enterprise are exposed to risk, though exploitation requires a valid account on the system. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and there are no reports of exploitation in the wild.

What to do: Check the IBM PSIRT advisory for CVE-2026-75624 and upgrade App Connect Enterprise to the fixed fix-pack/release levels for the 12.x and 13.x streams (any release beyond the listed ranges per IBM's guidance). Until patched, limit network reachability of ACE nodes, review and tighten authenticated user accounts and role/permission assignments that could be abused by the authorization bypass, and monitor logs for authenticated users accessing resources outside their normal scope.

Affected
IBM App Connect Enterprise13.0.1.0 through 13.0.8.1
IBM App Connect Enterprise12.0.1.0 through 12.0.12.27
Estimated exposure
moderate≈ low thousands of enterprise deployments (estimate; no public install counts) — App Connect Enterprise is enterprise integration middleware (successor to IBM Integration Bus) typically deployed behind firewalls by organizations worldwide, so the plausible affected install base is on the order of thousands of systems,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.

Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.