Description
IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass
Action: Patch Now
AI Analysis

Impact

The vulnerability is an authentication bypass in the SOAP/JMX connector of IBM WebSphere Application Server. An attacker who can reach the SOAP endpoint can issue JMX management commands without providing valid credentials, which may allow the attacker to read or modify management data, execute arbitrary code, or exfiltrate sensitive information. The weakness is a classic example of a missing or improperly implemented authentication control (CWE‑306), implying potential compromise of confidentiality, integrity, and availability of the application server and its hosted applications.

Affected Systems

IBM WebSphere Application Server 8.5.x versions prior to 8.5.5.31 and 9.0.x versions prior to 9.0.5.29 are affected. These versions expose the SOAP/JMX connector without proper authentication enforcement.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate risk. No EPSS value is supplied, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that there are no documented active exploitations to date. Attackers would need network access to the SOAP/JMX interface; with this access, they can bypass authentication and potentially gain privileged operations. While the impact is moderate, the ease of exploitation via network protocols makes patching advisable.

Generated by OpenCVE AI on September 19, 2026 at 10:52 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply IBM Fix Pack 9.0.5.29 or later (SB0030823) to IBM WebSphere Application Server 9.0
  • Apply IBM Fix Pack 8.5.5.31 or later to IBM WebSphere Application Server 8.5
  • If patching cannot be performed immediately, disable the SOAP/JMX connector or restrict network access to it to prevent unauthenticated access

Generated by OpenCVE AI on September 19, 2026 at 10:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-306
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:43.108Z

Reserved: 2026-06-08T02:48:19.225Z

Link: CVE-2026-11539

cve-icon Vulnrichment

Updated: 2026-09-19T14:10:00.853Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:00.340

Modified: 2026-09-22T19:32:25.730

Link: CVE-2026-11539

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:00:21Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function