What is CVE-2026-15435?
This vulnerability in specific IBM App Connect Enterprise versions allows a remote attacker to perform directory traversal and write arbitrary files on the system via a specially crafted URL with dot-dot sequences. Affected versions include 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.7.2, requiring immediate patching and URL filtering.
Azərbaycanca: IBM App Connect Enterprise-in müəyyən versiyalarında aşkar edilmiş bu boşluq uzaqdan hücumçuya xüsusi hazırlanmış URL vasitəsilə sistemdə kataloq keçidi (directory traversal) edərək ixtiyari fayllar yazmağa imkan verir. 12.0.1.0-12.0.12.27 və 13.0.1.0-13.0.7.2 versiyaları təsirə məruz qalır, dərhal yenilənmə və URL səviyyəsində filtrləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: IBM
FAQ2
Which specific versions of IBM App Connect Enterprise are affected by CVE-2026-15435?
The vulnerability affects versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.7.2.
What technique does a remote attacker use to write files via CVE-2026-15435?
The attacker performs directory traversal by sending a specially crafted URL containing dot-dot sequences.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.