CVE-2026-9074
Critical · CVSS 9.1IBM API Connect — Unauthenticated SQL Injection
- CVSS
- 9.1
- nvd
- EPSS
- 0.44%
- 35th pct
- KEV
- No
- Class
- other
- CWE-89
Description
IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.
Search profile — drives PoC discovery
Symbols password_resetreset_passwordpasswordResetforgot_passwordforgotPasswordsql_injectionsqliapi_connectapic
Keywords CVE-2026-9074IBM API ConnectSQL injectionpassword resetunauthenticated SQLiIBM APICCWE-8910.0.812.1.0
Versions: 10.0.8.0 through 10.0.8.9, 12.1.0.0 through 12.1.0.3
References
Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z