XML External Entity Injection Vulnerability in IBM App Connect Enterprise and Integration Bus
CVE-2026-17444

5.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
4 September 2026

What is CVE-2026-17444?

A vulnerability exists in IBM App Connect Enterprise and IBM Integration Bus for z/OS that could be exploited by a remote authenticated attacker to reveal sensitive information. This issue arises from improper handling of XML input which allows the attacker to manipulate XML external entities (XXE). If exploited, this could lead to unauthorized disclosure of confidential data, underscoring the importance of applying security patches and following best practices for XML processing.

Affected Version(s)

App Connect Enterprise 13.0.1.0 <= 13.0.8.1

App Connect Enterprise 12.0.1.0 <= 12.0.12.28

Integration Bus for z/OS 10.1.0.0 <= 10.1.0.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.