Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-3144: IBM API Connect Uses Default Credentials
CVE-2026-3144
CVE-2026-3144
Summary
IBM API Connect 12.1.0.0 to 12.1.0.3 uses default passwords. This can allow unauthorized access to the application. To fix this, update the credentials to strong, unique passwords.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | api connect | < 12.1.0.3 |
| ibm | api_connect |
>= 12.1.0.0, < 12.1.1.0 cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:* |
Original title
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
Original description
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
nvd CVSS3.1
8.1
Vulnerability type
CWE-1392
Published: 8 Jul 2026 · Updated: 23 Jul 2026 · First seen: 8 Jul 2026