CVE-2026-81832
moderateXXE in IBM App Connect Enterprise and Integration Bus for z/OS SAP Adapter
IBM App Connect Enterprise (13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.28) and the SAP Adapter of IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 are vulnerable to an XML external entity (XXE) injection flaw (CWE-611) in XML processing. An authenticated, low-privilege user (CVSS PR:L) who can supply crafted XML to affected parsing — such as message flows using the SAP Adapter that process untrusted XML documents or entity references — can cause the parser to resolve external entities. The CVSS vector shows scope change with high confidentiality impact and no integrity or availability impact, meaning an attacker's realistic gain is reading local files from the integration node and reaching internal network services (SSRF), not code execution or data modification. Any organization running the affected releases of App Connect Enterprise or the Integration Bus for z/OS SAP Adapter is affected. Exploitation is not currently known: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
What to do: Check IBM's security bulletin for CVE-2026-81832 and upgrade App Connect Enterprise to releases beyond 13.0.8.1 (13.x) and 12.0.12.28 (12.x), and apply IBM's fix for the Integration Bus for z/OS 10.1 SAP Adapter as specified in the advisory. Until patched, limit SAP Adapter flows to trusted XML sources and disable external entity/DOCTYPE resolution in XML parsing where the configuration supports it. Inventory integration nodes for use of the SAP Adapter and identify which run the affected version ranges to prioritize patching.
| IBM App Connect Enterprise | 13.0.1.0 through 13.0.8.1 |
| IBM App Connect Enterprise | 12.0.1.0 through 12.0.12.28 |
| IBM Integration Bus for z/OS (SAP Adapter) | 10.1.0.0 through 10.1.0.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.
- Vendors
- ibm
- Products
- app connect enterprise, integration bus for z\/os
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.