Denial of Service Vulnerability in IBM App Connect Enterprise and IBM Integration Bus
CVE-2026-17440
5.5MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 4 September 2026
What is CVE-2026-17440?
A vulnerability in IBM App Connect Enterprise and IBM Integration Bus allows a local attacker to exploit uncontrolled recursion. This can lead to a denial of service, affecting the availability of the product. Users of versions 13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.28, as well as IBM Integration Bus for z/OS versions 10.1.0.0 through 10.1.0.7, are advised to apply the relevant patches to mitigate this issue.
Affected Version(s)
App Connect Enterprise 13.0.1.0 <= 13.0.8.1
App Connect Enterprise 12.0.1.0 <= 12.0.12.28
Integration Bus for z/OS 10.1.0.0 <= 10.1.0.7