No advisories yet.
Solution
IBM strongly recommends addressing the vulnerability by applying the following fixes: IBM webMethods API Gateway - 10.11_Fix33 IBM webMethods API Gateway - 10.15_Fix28 IBM webMethods API Gateway - 11.1_Fix8 Above mentioned fixes can be installed using the tool - 'IBM webMethods Update Manager', which is available at: https://www.ibm.com/eserver/support/fixes/fixcentral
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7261122 |
|
Tue, 03 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to properly validate user-supplied input passed to the url parameter on the /createapi endpoint. An attacker can modify this parameter to use a file:// URI schema instead of the expected https:// schema, enabling unauthorized arbitrary file read access on the underlying server file system. | |
| Title | IBM webMethods API Management fails to validate user input and enables unauthorized arbitrary file read | |
| First Time appeared |
Ibm
Ibm webmethods Api Gateway On Prem |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:ibm:webmethods_api_gateway_on_prem:10.11:*:*:*:*:*:*:* cpe:2.3:a:ibm:webmethods_api_gateway_on_prem:10.11_fix3210.15:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm webmethods Api Gateway On Prem |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-03-03T19:38:30.609Z
Reserved: 2026-02-16T22:12:35.250Z
Link: CVE-2026-2606
No data.
Status : Awaiting Analysis
Published: 2026-03-03T20:16:49.783
Modified: 2026-03-03T21:52:29.877
Link: CVE-2026-2606
No data.
OpenCVE Enrichment
No data.