CVE-2026-9074
published 2026-07-08CVE-2026-9074: IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.28%
20.4th percentile
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | api_connect | — | — |
| ibm | api_connect | >= 10.0.8.0 < 10.0.8.9 | 10.0.8.9 |
| ibm | api_connect | >= 10.0.8.0 < 10.0.8.10 | 10.0.8.10 |
| ibm | api_connect | >= 12.1.0.0 < 12.1.1.0 | 12.1.1.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM API Connect up to 10.0.6.0 Password Reset sql injection
vuldb·2026-07-12·CVSS 9.8
CVE-2026-9074 [CRITICAL] IBM API Connect up to 10.0.6.0 Password Reset sql injection
A vulnerability described as critical has been identified in IBM API Connect. This affects an unknown function of the component Password Reset. Such manipulation leads to sql injection.
This vulnerability is traded as CVE-2026-9074. The attack may be launched remotely. There is no exploit available.
GHSA
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
ghsa_unreviewed·2026-07-08
CVE-2026-9074 [CRITICAL] CWE-89 IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-08
Published