← Back to CVE search

CVE-2026-9074

IBM API Connect

Description

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.

CVSS 9.1EPSS 0.281%Risk 0.93
View source
Published
2026-07-08 16:16:35
Affected versions
>=10.0.8.0,<10.0.8.9,>=12.1.0.0,<12.1.0.3
Type
Critical software
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N