SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15435

CRITICAL · CVSS 9.8 EPSS 0.50%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.7.2 are vulnerable to directory traversal attacks, enabling remote attackers to exploit specially crafted URL requests to write arbitrary files on the system. This critical vulnerability poses significant risks, including unauthorized access to sensitive data and potential system compromise. Organizations using these versions should prioritize immediate patching to mitigate the threat.

CVE
CVE-2026-15435
Severity
CRITICAL
CVSS
9.8
EPSS
0.50%

Original NVD Description

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

Related CVEs

Other vulnerabilities affecting the same vendor(s)