XML External Entity Injection Vulnerability in IBM App Connect Enterprise and Integration Bus
CVE-2026-17444
5.3MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 4 September 2026
What is CVE-2026-17444?
A vulnerability exists in IBM App Connect Enterprise and IBM Integration Bus for z/OS that could be exploited by a remote authenticated attacker to reveal sensitive information. This issue arises from improper handling of XML input which allows the attacker to manipulate XML external entities (XXE). If exploited, this could lead to unauthorized disclosure of confidential data, underscoring the importance of applying security patches and following best practices for XML processing.
Affected Version(s)
App Connect Enterprise 13.0.1.0 <= 13.0.8.1
App Connect Enterprise 12.0.1.0 <= 12.0.12.28
Integration Bus for z/OS 10.1.0.0 <= 10.1.0.7