CVE-2026-75624
moderateIncorrect authorization security bypass in IBM App Connect Enterprise
IBM App Connect Enterprise, an enterprise integration and messaging middleware product, is affected by an incorrect authorization flaw (CWE-863) in versions 13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.27. The issue can be triggered remotely by any authenticated user who sends a request to functionality where the product fails to correctly enforce its authorization checks, with no user interaction or special conditions required (CVSS AV:N/AC:L/PR:L/UI:N). An attacker who successfully exploits it can bypass security restrictions and gain unauthorized access to protected operations and data, with IBM scoring the potential impact as high on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). All customers running the affected version ranges of App Connect Enterprise are exposed to risk, though exploitation requires a valid account on the system. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and there are no reports of exploitation in the wild.
What to do: Check the IBM PSIRT advisory for CVE-2026-75624 and upgrade App Connect Enterprise to the fixed fix-pack/release levels for the 12.x and 13.x streams (any release beyond the listed ranges per IBM's guidance). Until patched, limit network reachability of ACE nodes, review and tighten authenticated user accounts and role/permission assignments that could be abused by the authorization bypass, and monitor logs for authenticated users accessing resources outside their normal scope.
| IBM App Connect Enterprise | 13.0.1.0 through 13.0.8.1 |
| IBM App Connect Enterprise | 12.0.1.0 through 12.0.12.27 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.