CVE-2026-3144
published 2026-07-08CVE-2026-3144: IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the…
PriorityP359critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.41%
33.3th percentile
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | api_connect | >= 12.1.0.0 < 12.1.0.3 | 12.1.0.3 |
| ibm | api_connect | >= 12.1.0.0 < 12.1.1.0 | 12.1.1.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM API Connect up to 12.1.0.3 default credentials
vuldb·2026-07-12·CVSS 9.8
CVE-2026-3144 [CRITICAL] IBM API Connect up to 12.1.0.3 default credentials
A vulnerability was found in IBM API Connect up to 12.1.0.3 and classified as problematic. Impacted is an unknown function. Such manipulation leads to use of default credentials.
This vulnerability is listed as CVE-2026-3144. The attack may be performed from remote. There is no available exploit.
GHSA
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
ghsa_unreviewed·2026-07-08
CVE-2026-3144 [HIGH] CWE-1392 IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-08
Published