XML External Entity Injection Vulnerability in IBM App Connect Enterprise and Integration Bus
CVE-2026-17443
5.3MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 4 September 2026
What is CVE-2026-17443?
The vulnerability in IBM App Connect Enterprise and IBM Integration Bus arises from an XML External Entity (XXE) injection flaw. This flaw could potentially enable a remote authenticated attacker to exploit the application, leading to unauthorized access to sensitive data. Versions affected include IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, 12.0.1.0 through 12.0.12.28, and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7. Addressing this vulnerability is crucial to safeguard against data exposure and maintain the integrity of sensitive information within these systems.
Affected Version(s)
App Connect Enterprise 13.0.1.0 <= 13.0.8.1
App Connect Enterprise 12.0.1.0 <= 12.0.12.28
Integration Bus for z/OS 10.1.0.0 <= 10.1.0.7