CVE Tools

CVE-2026-3602: SQL Injection in IBM App Connect Enterprise Leads to Code Execution

OX SecurityBy Nir Zadok, Moshe Siman Tov Bustan3 min read

PoC publicIBM App Connect EnterpriseIBM Integration Bus for z/OS

Our summary

Researchers at OX Security discovered a SQL injection flaw in IBM App Connect Enterprise and IBM Integration Bus for z/OS, tracked as CVE-2026-3602. This vulnerability enables attackers to create arbitrary files on a victim's system through a maliciously crafted SQL file. If exploited successfully, it can lead to remote command execution and full system compromise. The flaw requires user interaction, typically via social engineering tactics to lure victims into importing the malicious file. IBM has released patches for affected versions of its software.

Read at OX Security

Below is the opening; the full story is at OX Security.

From OX Security

From an innocent-looking SQL import to startup-folder persistence: Understanding the risk in patched IBM App Connect Enterprise Toolkits

Overview

OX Research found and disclosed a SQL injection vulnerability in the IBM App Connect Enterprise and IBM Integration Bus for z/OS Toolkit.

The SQL injection vulnerability allows the attacker to create arbitrary files on the victim’s machine without the victim’s knowledge. Successful exploitation of this vulnerability requires user interaction, so a remote attacker would need to use social engineering techniques to trick the user into performing actions that trigger the vulnerability.…

Continue at OX Security

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store