CVE-2025-36361: IBM App Connect Enterprise

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due to missing authorization.

Affected products

  • IBM App Connect Enterprise: from 12.0.1.0, up to and including 12.0.12.17; from 13.0.1.0, up to and including 13.0.4.2

Published 2025-10-24. Last modified 2026-06-17.