Critical authentication bypass in IBM API Connect prompts urgent patching

by

IBM said in a security bulletin from IBM that customers should quickly patch a critical vulnerability in API Connect that could allow remote attackers to bypass authentication. The flaw, tracked as CVE-2025-13915, affects versions 10.0.8.0 through 10.0.8.5 and 10.0.11.0 and can grant unauthorized access with no user interaction.

KEY FACTS

  • Incident Authentication bypass vulnerability in API Connect
  • Affected versions 10.0.8.0 through 10.0.8.5 and 10.0.11.0
  • Identifier CVE-2025-13915
  • Mitigation Interim fixes available and disable self-service sign-up if unable to patch

API Connect is a full lifecycle API gateway that provides developer onboarding via a self-service portal and supports SOAP, REST, GraphQL and event APIs. The platform also includes AI features to automate tasks across the API lifecycle.

Analyst Sanchit Vir Gogia (chief analyst at Greyhound Research): “It is better understood as a moment where a long standing architectural assumption finally breaks in the open.” He said the weakness maps to CWE-305 and that authentication enforcement can be circumvented, allowing downstream services to inherit unverified identity.

Interim fixes are available for each affected version with update details for VMware, OCP/CP4I and Kubernetes. Customers unable to install the interim fix should disable self-service sign-up on their Developer Portal, according to the advisory.

The advisory also notes that image overrides used for fixes must be removed when upgrading to the next release or fixpack. Left in place, overrides can create persistent shadow state that increases governance and operational risk. The vulnerability was discovered during internal testing; there is no public indication of exploitation in the disclosure.

WHY IT MATTERS

An authentication bypass in a central API gateway can let many services rely on unearned trust and increase exposure across the platform. Rapid application of the provided fixes and review of API governance and inventories can reduce the risk.