Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-3144: IBM API Connect Uses Default Credentials
CVE-2026-3144 · published 2 months ago
Summary
IBM API Connect 12.1.0.0 to 12.1.0.3 uses default passwords. This can allow unauthorized access to the application. To fix this, update the credentials to strong, unique passwords.
What to do
- Update ibm api connect to version 12.1.0.3 or later.
- Update ibm api_connect to version 12.1.1.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | api connect | < 12.1.0.3 |
| ibm | api_connect |
>= 12.1.0.0, < 12.1.1.0 cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:* |
Original advisory text
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
Severity
9.8
Critical
CVSS 3.1: 8.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-1392Use of Default Credentials
Timeline
Published8 Jul 2026
Updated27 Sep 2026
First seen8 Jul 2026
Track software like this
Free during beta