CVE-2026-9074: IBM API Connect SQL Injection
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
Other sources
IBM API Connect contains an unauthenticated SQL injection vulnerability in the password reset functionality.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9074?
The severity of CVE-2026-9074 is rated as critical with a score of 9.8.
How do I fix CVE-2026-9074?
To fix CVE-2026-9074, update IBM API Connect to versions 10.0.8.10 or 12.1.0.4 or later.
What type of vulnerability is CVE-2026-9074?
CVE-2026-9074 is an unauthenticated SQL injection vulnerability found in the password reset functionality of IBM API Connect.
Which versions of IBM API Connect are affected by CVE-2026-9074?
CVE-2026-9074 affects IBM API Connect versions 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3.
Can CVE-2026-9074 be exploited remotely?
Yes, CVE-2026-9074 can be exploited remotely due to the unauthenticated nature of the SQL injection vulnerability.