Skip to content
Threat Feed
high advisory

XML External Entity Vulnerability in IBM App Connect Enterprise and Integration Bus

IBM App Connect Enterprise and IBM Integration Bus for z/OS SAP Adapter components are susceptible to an XML External Entity (XXE) vulnerability, potentially allowing unauthenticated information disclosure or denial of service.

CVE search metadata

CVE search record: CVE-2026-81832. Severity: high. CVSS: 7.7. KEV: no. Product: App Connect Enterprise (13.0.1.0 - 13.0.8.1, 12.0.1.0 - 12.0.12.28), Integration Bus for z/OS (10.1.0.0 - 10.1.0.7). Brief: XML External Entity Vulnerability in IBM App Connect Enterprise and Integration Bus. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-81832/

IBM App Connect Enterprise and IBM Integration Bus for z/OS contain a security vulnerability in their SAP Adapter component (CVE-2026-81832). The issue is classified as an XML External Entity (XXE) injection flaw. An unauthenticated remote attacker can exploit this vulnerability by sending a maliciously crafted XML request to the affected SAP Adapter interface. Successful exploitation may lead to the disclosure of sensitive internal data, such as local configuration files or credential artifacts, or result in a denial of service (DoS) by causing the application to parse external entities that resolve to large files or infinite URI streams. The vulnerability impacts versions 13.0.1.0 through 13.0.8.1 and 12.0.1.0 through 12.0.12.28 for App Connect Enterprise, and versions 10.1.0.0 through 10.1.0.7 for IBM Integration Bus for z/OS.

Impact

Successful exploitation of this XXE vulnerability permits an attacker to bypass data confidentiality boundaries by reading unauthorized files from the server's filesystem. This can lead to the exposure of credentials, environment configuration secrets, and system metadata. Furthermore, an attacker can leverage the XML parser's resource processing to consume excessive memory or CPU cycles, leading to application downtime for legitimate users. This risk is particularly severe in enterprise environments where these integration platforms manage sensitive cross-system communication.

Recommendation

Prioritize the identification and patching of all IBM App Connect Enterprise and IBM Integration Bus for z/OS instances.

  • Upgrade IBM App Connect Enterprise to a version outside the vulnerable range (13.0.1.0-13.0.8.1 and 12.0.1.0-12.0.12.28).
  • Upgrade IBM Integration Bus for z/OS SAP Adapter to a version outside the vulnerable range (10.1.0.0-10.1.0.7).
  • Review web application firewall logs for incoming HTTP traffic containing XML payloads with !ENTITY or !DOCTYPE declarations targeting the SAP Adapter endpoints.

Immediate actions

Inventory all IBM App Connect Enterprise and IBM Integration Bus deployments and apply relevant patches.

IT Operations 72h

Mitigations

Patch affected versions of App Connect Enterprise and Integration Bus for z/OS.

immediate IT Operations

CVE-2026-81832