CVE-2026-15435 – IBM App Connect Enterprise
“When file access and command execution flaws exist together, attackers gain multiple paths to compromise.”
This update addresses multiple vulnerabilities affecting IBM App Connect Enterprise. CVE-2026-15435 has a CVSS score of 9.8, Critical severity. It is a path traversal vulnerability that allows a remote attacker to send a specially crafted URL containing “/../” sequences to write arbitrary files on the system. CVE-2026-14522 has a CVSS score of 8.8, High severity. It allows remote arbitrary command execution due to improper neutralization of CRLF characters. CVE-2026-12947 has a CVSS score of 7.5, High severity. It exposes potentially sensitive information stored in log files that may be accessible to a local user. CVE-2026-14519 has a CVSS score of 7.5, High severity. It is a path traversal vulnerability that allows a remote attacker to read arbitrary files. No verified real-world exploitation has been reported for these vulnerabilities.
The vulnerabilities affect IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2 and 12.0.1.0 through 12.0.12.27. Together, they expose systems to unauthorized file read and write operations, remote command execution, and disclosure of sensitive information. Based on the supplied assessment, CVE-2026-14522 has Remote Code Execution (RCE) characteristics, while CVE-2026-15435 and CVE-2026-14519 have Elevation of Privilege (EoP) characteristics. Organizations should prioritize applying the latest IBM security updates to affected deployments.
Key Details
- Affected Product
- Ibm App Connect Enterprise
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-22