Sensitive Information Exposure in IBM App Connect Enterprise and Integration Bus
CVE-2026-16689

6.2MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
4 September 2026

What is CVE-2026-16689?

A vulnerability in IBM App Connect Enterprise versions 13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.28, along with IBM Integration Bus for z/OS versions 10.1.0.0 through 10.1.0.7, allows local attackers to exploit improper credential logging. This could lead to unauthorized access to sensitive information, making it crucial for users to apply available patches to mitigate potential risks.

Affected Version(s)

App Connect Enterprise 13.0.1.0 <= 13.0.8.1

App Connect Enterprise 12.0.1.0 <= 12.0.12.28

Integration Bus for z/OS 10.1.0.0 <= 10.1.0.7

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.