logo

CVE-2026-15435: IBM App Connect Enterprise Path Traversal — Arbitrary File Write (CVSS 9.8)

ID: eac0eabc-72a4-5992-889f-efc2c399e011

STIX ID: report--eac0eabc-72a4-5992-889f-efc2c399e011

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-31

Date Updated: 2026-08-01

...
...

## Executive Summary IBM disclosed CVE-2026-15435, a critical (CVSS 3.1 9.8) path traversal vulnerability in IBM App Connect Enterprise (v12 and v13) that allows unauthenticated, network-accessible attackers to use /../ sequences to write arbitrary files anywhere on the filesystem — enabling web shells, configuration tampering, or remote code execution; affected versions and remediation/mitigation guidance are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.