Vulnerability Description
IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to properly validate user-supplied input passed to the url parameter on the /createapi endpoint. An attacker can modify this parameter to use a file:// URI schema instead of the expected https:// schema, enabling unauthorized arbitrary file read access on the underlying server file system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Webmethods Api Gateway | 10.11 |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7261122Vendor Advisory
FAQ
What is CVE-2026-2606?
CVE-2026-2606 is a vulnerability with a CVSS score of 6.5 (MEDIUM). IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to properly validate user-supplied input passed to the...
How severe is CVE-2026-2606?
CVE-2026-2606 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-2606?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Webmethods Api Gateway.