Jan 1, 2026·6 min read·13 visits
IBM API Connect has a CVSS 9.8 hole in its Developer Portal. If 'self-service sign-up' is enabled, the authentication logic fails to properly validate user creation requests. This allows remote attackers to bypass identity verification entirely, potentially registering as administrators or hijacking existing accounts without credentials. IBM has released iFixes; immediate patching or disabling sign-up is required.
A critical authentication bypass in IBM API Connect's Developer Portal allows unauthenticated attackers to hijack accounts or create admin users simply by manipulating the self-service sign-up flow.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H| Product | Affected Versions | Fixed Version |
|---|---|---|
IBM API Connect IBM | 10.0.8.0 - 10.0.8.5 | 10.0.8.5-iFix |
IBM API Connect IBM | 10.0.11.0 | 10.0.11.0-iFix |
| Attribute | Detail |
|---|---|
| CWE | CWE-305 (Authentication Bypass) |
| CVSS v3.1 | 9.8 (Critical) |
| Attack Vector | Network (Remote) |
| Privileges Required | None |
| EPSS Score | 0.37% (Low/Emerging) |
| Exploit Status | No Public PoC / Internal Discovery |
Authentication Bypass by Primary Weakness