Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-9074: IBM API Connect Password Reset SQL Injection
CVE-2026-9074 · published 2 months ago
Summary
IBM API Connect versions 10.0.8.0 to 10.0.8.9 and 12.1.0.0 to 12.1.0.3 have a security weakness in the password reset feature. An attacker can access sensitive data without needing a password. To stay secure, update to the latest version of IBM API Connect or apply the recommended patches.
What to do
- Update ibm api connect to version 10.0.8.9 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | api connect | < 10.0.8.9 |
| ibm | api_connect |
>= 10.0.8.0, < 10.0.8.10 >= 12.1.0.0, < 12.1.1.0 cpe:2.3:a:ibm:api_connect:*:*:*:*:*:*:*:* |
Original advisory text
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
Severity
9.8
Critical
CVSS 3.1: 9.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published8 Jul 2026
Updated27 Sep 2026
First seen8 Jul 2026
Track software like this
Free during beta