CVE-2026-3144
Analyzed Analyzed - Analysis Complete

IBM API Connect Default Credentials Exposure

Vulnerability report for CVE-2026-3144, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-08

Last updated on: 2026-07-10

Assigner: IBM Corporation

Description

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-08
Last Modified
2026-07-10
Generated
2026-07-11
AI Q&A
2026-07-09
EPSS Evaluated
2026-07-09
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm api_connect From 12.1.0.0 (inc) to 12.1.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1392 The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Mitigation Strategies

The vulnerability involves IBM API Connect versions 12.1.0.0 through 12.1.0.3 using default credentials, which could allow unauthorized access before the system enforces a credential update.

Immediate mitigation steps should include changing any default credentials on the affected IBM API Connect installations to strong, unique passwords to prevent unauthorized access.

Additionally, ensure that the system enforces credential updates promptly and consider restricting network access to the application to trusted users only.

Executive Summary

IBM API Connect versions 12.1.0.0 through 12.1.0.3 use default credentials that allow an attacker to gain unauthorized access to the application before the system enforces a credential update.

Impact Analysis

This vulnerability can allow an attacker to gain unauthorized access to the IBM API Connect application, potentially leading to full compromise of confidentiality, integrity, and availability of the system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3144. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart