Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
Published: 2026-07-28
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM WebSphere Application Server 8.5 and 9.0 contain a broken access control flaw in the administrative console that permits an attacker to elevate privileges. The vulnerability is classified as CWE‑306, and if exploited, an attacker could gain full administrative rights, allowing arbitrary configuration changes, code deployment, and potential control of the entire application server instance. This can compromise confidentiality, integrity, and availability of services running on the affected server.

Affected Systems

The flaw impacts IBM WebSphere Application Server version 8.5 for all sub‑versions up to 8.5.5.30 and version 9.0 up to 9.0.5.28. Microsoft‑style patch numbering is used, and users should refer to IBM’s fix pack or interim fix DT496500 to remediate the vulnerability.

Risk and Exploitability

The CVSS score of 9.8 classifies this as a critical risk, but the EPSS score is below 1 %, suggesting a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker with access to the administrative console—potentially a user with limited privileges—could exploit this weakness to perform privilege escalation. The impact is system‑wide if administrative control is achieved. Applying the specified interim fix or upgrading to the relevant higher‑level fix pack will eliminate the risk.

Generated by OpenCVE AI on August 3, 2026 at 14:14 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR DT496500. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496500  https://www.ibm.com/support/pages/node/7281559 --OR-- · Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).  For V8.5.0.0 through 8.5.5.30: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496500 https://www.ibm.com/support/pages/node/7281559 --OR-- · Apply Fix Pack 8.5.5.31 or later (targeted availability 3Q2026).  Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Apply the IBM interim fix DT496500 after upgrading to the required minimal fix pack level for your WebSphere version.
  • Upgrade directly to Fix Pack 9.0.5.29 or later for WebSphere 9, or 8.5.5.31 or later for WebSphere 8.5, which incorporates the fix.
  • Restrict network access to the administrative console to a separate network segment or trusted IP addresses to mitigate potential exploitation while a patch is pending.

Generated by OpenCVE AI on August 3, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
Title IBM WebSphere Application Server is affected by a privilege escalation
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-306
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T03:55:19.397Z

Reserved: 2026-07-02T03:46:49.452Z

Link: CVE-2026-14446

cve-icon Vulnrichment

Updated: 2026-07-29T13:34:16.346Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T21:17:25.660

Modified: 2026-08-05T16:26:56.080

Link: CVE-2026-14446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:15:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function