Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-3144: IBM API Connect Uses Default Credentials

CVE-2026-3144 · published 2 months ago
Summary

IBM API Connect 12.1.0.0 to 12.1.0.3 uses default passwords. This can allow unauthorized access to the application. To fix this, update the credentials to strong, unique passwords.

What to do
  • Update ibm api connect to version 12.1.0.3 or later.
  • Update ibm api_connect to version 12.1.1.0 or later.
Affected software
VendorProductAffected versions
ibm api connect < 12.1.0.3
ibm api_connect >= 12.1.0.0, < 12.1.1.0
cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:*
Original advisory text
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
Severity
9.8 Critical
CVSS 3.1: 8.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-1392Use of Default Credentials
Timeline
Published8 Jul 2026
Updated27 Sep 2026
First seen8 Jul 2026
Sources
CVE-2026-3144 · NVD
CVE-2026-3144 · MITRE
Track software like this
Free during beta