CVE-2026-75624: IBM App Connect Enterprise
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.
Affected products
- IBM App Connect Enterprise: from 12.0.1.0, before 12.0.12.28 (fixed in 12.0.12.28); from 13.0.1.0, before 13.0.8.2 (fixed in 13.0.8.2)
Published 2026-09-10. Last modified 2026-09-16.