SB2026092956 - Multiple vulnerabilities in IBM App Connect Enterprise



SB2026092956 - Multiple vulnerabilities in IBM App Connect Enterprise

Published: September 29, 2026

Security Bulletin ID SB2026092956
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Unsafe reflection (CVE-ID: CVE-2026-19032)

CWE-ID: CWE-470 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use of externally controlled input to select classes or code in JDKFromStringDeserializer.NioPathHelper.deserialize when deserializing untrusted JSON into a java.nio.file.Path field. A remote attacker can supply a specially crafted URI scheme to drive FileSystemProvider resolution and cause a denial of service.

Exploitation occurs during readValue, and meaningful side effects beyond the reported availability impact depend on the presence of a side-effecting third-party FileSystemProvider on the classpath.


2) Deserialization of Untrusted Data (CVE-ID: CVE-2026-83557)

CWE-ID: CWE-502 - Deserialization of Untrusted Data

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to instantiate an unintended object and disclose, modify, or affect data handling.

The vulnerability exists due to deserialization of untrusted data in DefaultBaseTypeLimitingValidator when processing polymorphic type identifiers for @JsonTypeInfo-annotated Comparable-typed values without a custom PolymorphicTypeValidator. A remote attacker can supply a crafted type identifier to instantiate an attacker-chosen Comparable implementation to disclose, modify, or affect data handling.

Only the default, unconfigured validator path reached through bare @JsonTypeInfo usage is affected; configurations using activateDefaultTyping() with an explicit restrictive PolymorphicTypeValidator are not affected.


3) Resource exhaustion (CVE-ID: CVE-2026-68497)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in CoreXMLDeserializers when deserializing JSON string values into javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar fields. A remote attacker can send a specially crafted request to cause a denial of service.

The issue is reachable with the default mapper configuration and does not require polymorphic typing or special configuration.


Remediation

Install update from vendor's website.