CVE-2026-15435: IBM App Connect Enterprise Path Traversal — Arbitrary File Write (CVSS 9.8)
ID: eac0eabc-72a4-5992-889f-efc2c399e011
STIX ID: report--eac0eabc-72a4-5992-889f-efc2c399e011
Feed Name: CosmicBytez Labs
Threat Score
## Executive Summary IBM disclosed CVE-2026-15435, a critical (CVSS 3.1 9.8) path traversal vulnerability in IBM App Connect Enterprise (v12 and v13) that allows unauthenticated, network-accessible attackers to use /../ sequences to write arbitrary files anywhere on the filesystem — enabling web shells, configuration tampering, or remote code execution; affected versions and remediation/mitigation guidance are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
