IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass

Date:

Share post:

Dec 31, 2026Ravie LakshmananAPI Security / Vulnerability

IBM has disclosed details of a critical security flaw in API Connect that could allow attackers to gain remote access to the application.

The vulnerability, tracked as CVE-2025-13915, is rated 9.8 out of a maximum of 10.0 on the CVSS scoring system. It has been described as an authentication bypass flaw.

“IBM API Connect could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application,” the tech giant said in a bulletin.

The shortcoming affects the following versions of IBM API Connect –

  • 10.0.8.0 through 10.0.8.5
  • 10.0.11.0
Cybersecurity

Customers are advised to follow the steps outlined below –

  • Download the fix from Fix Central
  • Extract the files: Readme.md and ibm-apiconnect--ifix.13195.tar.gz
  • Apply the fix based on the appropriate API Connect version

“Customers unable to install the interim fix should disable self-service sign-up on their Developer Portal if enabled, which will help minimise their exposure to this vulnerability,” the company added.

API Connect is an end-to-end application programming interface (API) solution that allows organizations to create, test, manage, and secure APIs located on cloud and on-premises. It’s used by companies like Axis Bank, Bankart, Etihad Airways, Finologee, IBS Bulgaria, State Bank of India, Tata Consultancy Services, and TINE.

While there is no evidence of the vulnerability being exploited in the wild, users are advised to apply the fixes as soon as possible for optimal protection.

Source link

spot_img

Related articles

Nintendo, Sony And Xbox Update “Safer Gaming” Principles

In 2020, the major players in the console space Nintendo, Sony and Xbox announced a "shared commitment to...

Patch Tuesday, January 2026 Edition – Krebs on Security

Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and...

Some Motherboard UEFIs Are Injecting Software Into Windows

Following my article about BitLocker encrypting the OS drive on my Asus laptop without my consent, I began...

How to Digitalize Education Fairs and Maximize Impact: The Educoway Case

Organizing education fairs is no small task. From registering participants and managing check-ins to capturing leads for exhibitors,...