CVE Tools
Back to feed
PoC public IBM App Connect Enterprise rce IBM Integration Bus for z/OS IBM web-app

CVE-2026-3602: SQL Injection in IBM App Connect Enterprise Leads to Code Execution

OX Security·By Nir Zadok, Moshe Siman Tov Bustan··3 min read
CVE Tools coverage

Researchers at OX Security discovered a SQL injection flaw in IBM App Connect Enterprise and IBM Integration Bus for z/OS, tracked as CVE-2026-3602. This vulnerability enables attackers to create arbitrary files on a victim's system through a maliciously crafted SQL file. If exploited successfully, it can lead to remote command execution and full system compromise. The flaw requires user interaction, typically via social engineering tactics to lure victims into importing the malicious file. IBM has released patches for affected versions of its software.

From an innocent-looking SQL import to startup-folder persistence: Understanding the risk in patched IBM App Connect Enterprise Toolkits

Overview

OX Research found and disclosed a SQL injection vulnerability in the IBM App Connect Enterprise and IBM Integration Bus for z/OS Toolkit.

The SQL injection vulnerability allows the attacker to create arbitrary files on the victim’s machine without the victim’s knowledge. Successful exploitation of this vulnerability requires user interaction, so a remote attacker would need to use social engineering techniques to trick the user into performing actions that trigger the vulnerability.…

Continue reading on OX Security