Skip to content
IBMCVE-2026-9074

IBM API Connect: SQL injection

Critical9.1CVE-2026-9074 · Published Jul 8, 2026 · updated Jul 10, 2026

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.

IBM advisory

Affected versions

PackageAffectedFixed in
API Connect
Product
>= 10.0.8.0, < 10.0.8.910.0.8.9
<= 12.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-89

More IBM advisories

All IBM
Advisory
IBM PowerVM Novalink: denial of service
High7.5Jul 17
IBM Langflow OSS: code injection
Critical9.9Jul 17
IBM Db2: remote code execution
High7.8Jul 17
IBM Langflow OSS: missing authentication
Critical9.8Jul 17
IBM Langflow OSS: code injection
Critical9.8Jul 17
IBM API Connect: attacker could gain unauthorized access to the application
High8.1Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.