CVE-2026-15435
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- 0.73%
- 51th pct
- KEV
- No
- Class
- other
- CWE-22
Description
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
References
Status: profiled · ingested 2026-08-05T18:00:56.000Z