SB2026092810 - Multiple vulnerabilities in IBM App Connect Enterprise
Published: September 28, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Improper Handling of Alternate Encoding (CVE-ID: CVE-2026-10050)
CWE-ID: CWE-173 - Improper Handling of Alternate Encoding
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper handling of alternate encoding in DigestAuthentication.apply() when computing Digest authentication response hashes using ISO-8859-1 encoding. A remote attacker can use a password variant in which non-Latin-1 characters are replaced with '?' characters to bypass authentication.
Successful exploitation requires knowledge of the target username and a password containing characters outside the U+00FF range.
2) Information disclosure (CVE-ID: CVE-2026-10051)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper state management in HttpConnection._trailers when processing consecutive HTTP/1.1 keep-alive requests with trailers. A remote attacker can send a request with crafted trailers followed by another request on the same connection to disclose sensitive information.
The issue is limited to reuse of stale trailer data across requests on the same keep-alive connection and is not cross-connection.
3) Input validation error (CVE-ID: CVE-2026-6790)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass host-based access controls and interfere with hostname-based security decisions.
The vulnerability exists due to improper input validation in HTTP/2 and HTTP/3 server-side request handling when processing requests with mismatched :authority and Host values. A remote attacker can send a specially crafted request containing conflicting host identities to bypass host-based access controls and interfere with hostname-based security decisions.
Different layers may interpret different host values from the same request, which can affect virtual host isolation, multi-tenant routing, redirect or callback URL construction, proxy trust chains, and logging.
Remediation
Install update from vendor's website.