Code Execution Vulnerability in IBM App Connect Enterprise Software
CVE-2026-17133

7.8HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 September 2026

What is CVE-2026-17133?

A vulnerability in IBM App Connect Enterprise allows local attackers to execute arbitrary code due to improper handling of special elements in an operating system command. Attackers exploiting this flaw could gain unauthorized access to system functionalities, potentially leading to further exploitation of the software. Users are advised to apply available patches and conduct thorough security assessments to mitigate associated risks.

Affected Version(s)

App Connect Enterprise 13.0.1.0 <= 13.0.8.0

App Connect Enterprise 12.0.1.0 <= 12.0.12.27

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.