Sensitive Information Exposure in IBM App Connect Enterprise and Integration Bus
CVE-2026-19649

6.2MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
4 September 2026

What is CVE-2026-19649?

IBM App Connect Enterprise versions from 13.0.1.0 to 13.0.8.1 and 12.0.1.0 to 12.0.12.28, as well as IBM Integration Bus for z/OS from 10.1.0.0 to 10.1.0.7, have a vulnerability that could allow local attackers to access sensitive information. This issue arises from improper logging practices of database credentials, creating a risk of credential leakage. Organizations using these versions must take appropriate precautions to secure their environments and apply recommended patches from IBM to mitigate this risk.

Affected Version(s)

App Connect Enterprise 13.0.1.0 <= 13.0.8.1

App Connect Enterprise 12.0.1.0 <= 12.0.12.28

Integration Bus for z/OS 10.1.0.0 <= 10.1.0.7

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.