CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-9074

Critical · CVSS 9.1

IBM API Connect — Unauthenticated SQL Injection

CVSS
9.1
nvd
EPSS
0.44%
35th pct
KEV
No
Class
other
CWE-89

Description

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.

Search profile — drives PoC discovery

Symbols password_resetreset_passwordpasswordResetforgot_passwordforgotPasswordsql_injectionsqliapi_connectapic
Keywords CVE-2026-9074IBM API ConnectSQL injectionpassword resetunauthenticated SQLiIBM APICCWE-8910.0.812.1.0
Versions: 10.0.8.0 through 10.0.8.9, 12.1.0.0 through 12.1.0.3

References

Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z