IBM has disclosed a critical authentication bypass vulnerability in API Connect that could let a remote attacker gain unauthorized access to the application. The issue is tracked as CVE-2025-13915 and carries a CVSS score of 9.8.
The flaw affects API Connect versions 10.0.8.0 through 10.0.