{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aibmapp_connect_enterprise13.0.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-17133"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["App Connect Enterprise (13.0.1.0-13.0.8.0, 12.0.1.0-12.0.12.27)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","command-injection","cve"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM App Connect Enterprise, specifically versions 13.0.1.0 through 13.0.8.0 and 12.0.1.0 through 12.0.12.27, is vulnerable to a command injection flaw identified as CVE-2026-17133. The vulnerability stems from improper neutralization of special elements used in OS commands. A local attacker can exploit this weakness to execute arbitrary code with the privileges of the service user running the App Connect Enterprise process. This represents a significant risk to the integrity and availability of the host system. Defenders should prioritize patching, as this vulnerability allows for post-exploitation activities including lateral movement and privilege escalation on the affected host.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows a local attacker to execute arbitrary OS commands on the host running the IBM App Connect Enterprise instance. This can lead to full system compromise, data exfiltration, or the deployment of persistent malicious payloads. Given the nature of enterprise integration software, the compromised host likely has access to sensitive internal network segments or downstream databases.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade IBM App Connect Enterprise to the latest secure version addressing CVE-2026-17133 immediately.\u003c/li\u003e\n\u003cli\u003eImplement strict principle of least privilege for the service account running the App Connect Enterprise integration node.\u003c/li\u003e\n\u003cli\u003eReview system logs for unexpected child processes spawned by the IBM App Connect Enterprise process binary.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T21:35:36Z","date_published":"2026-09-14T21:35:36Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ibm-app-connect-command-injection/","summary":"IBM App Connect Enterprise versions 13.0.x and 12.0.x contain a command injection vulnerability (CVE-2026-17133) that allows local attackers to execute arbitrary OS commands.","title":"Command Injection Vulnerability in IBM App Connect Enterprise","url":"https://feed.craftedsignal.io/briefs/2026-09-ibm-app-connect-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}