Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-3144: IBM API Connect Uses Default Credentials

CVE-2026-3144 CVE-2026-3144
Summary

IBM API Connect 12.1.0.0 to 12.1.0.3 uses default passwords. This can allow unauthorized access to the application. To fix this, update the credentials to strong, unique passwords.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ibm api connect < 12.1.0.3
ibm api_connect >= 12.1.0.0, < 12.1.1.0
cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*
Original title
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
Original description
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
nvd CVSS3.1 8.1
Vulnerability type
CWE-1392
Published: 8 Jul 2026 · Updated: 23 Jul 2026 · First seen: 8 Jul 2026