CVE-2026-3144: IBM API Connect Default Credentials
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
Other sources
IBM API Connect uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Before the system enforces a credential update, change IBM API Connect default credentials for 12.1.0.0 through 12.1.0.3 to unique credentials to prevent unauthorized access.
IBM API Connect default credentials = Change from default credentials to unique credentials before the system enforces a credential update
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3144?
The severity of CVE-2026-3144 is critical with a score of 9.8.
How do I fix CVE-2026-3144?
To fix CVE-2026-3144, update to the latest version of IBM API Connect which addresses the default credentials issue.
What systems are affected by CVE-2026-3144?
CVE-2026-3144 affects IBM API Connect versions 12.1.0.0 through 12.1.0.3.
What does CVE-2026-3144 vulnerability expose?
CVE-2026-3144 exposes IBM API Connect to unauthorized access due to the use of default credentials.
Is authentication required to exploit CVE-2026-3144?
No, CVE-2026-3144 does not require authentication for an attacker to exploit the vulnerability.