SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-9074

CRITICAL · CVSS 9.1 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

IBM API Connect versions 10.0.8.0 to 10.0.8.9 and 12.1.0.0 to 12.1.0.3 are vulnerable to an unauthenticated SQL injection in the password reset feature, allowing attackers to manipulate database queries. This critical vulnerability can lead to unauthorized access and potential data breaches. Organizations using these versions should prioritize immediate patching to mitigate risks associated with this flaw.

CVE
CVE-2026-9074
Severity
CRITICAL
CVSS
9.1
EPSS
0.28%

Original NVD Description

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.

Related CVEs

Other vulnerabilities affecting the same vendor(s)