CVE-2026-75624

8.8

IBM · App Connect Enterprise

IBM App Connect Enterprise contains an authorization flaw that allows authenticated remote attackers to bypass security restrictions.

Executive summary

A remote authenticated attacker can bypass security restrictions in IBM App Connect Enterprise, potentially leading to full compromise of the affected environment.

Vulnerability

This vulnerability is caused by incorrect authorization (CWE-863), which allows a remote attacker with low-level privileges to perform actions or access data outside of their authorized scope.

Business impact

With a CVSS score of 8.8, this vulnerability represents a high-risk security flaw. Successful exploitation could allow an attacker to gain unauthorized access to sensitive data, manipulate business-critical workflows, or disrupt services, resulting in significant operational and reputational damage.

Remediation

Immediate Action: Apply the vendor-provided fix by upgrading to IBM App Connect Enterprise 13.0.8.2 or applying the relevant APAR (IT49854) as detailed in the official IBM support advisory.

Proactive Monitoring: Monitor system and application access logs for unusual patterns, such as unexpected API calls or unauthorized attempts to access administrative functions by low-privileged user accounts.

Compensating Controls: Implement strict network segmentation and access control lists to limit the exposure of the App Connect interface to untrusted networks, and ensure that Web Application Firewalls are configured to inspect traffic for signs of authorization bypass attempts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS severity and the potential for unauthorized access to business-critical integrations, organizations should prioritize the deployment of the provided IBM patches. Administrators must verify that all instances are updated to the specified versions to eliminate this authorization flaw and reduce the attack surface.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources