Description
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
Published: 2026-07-28
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM WebSphere Application Server 8.5 and 9.0 allow a remote attacker to bypass authentication by sending a specially crafted unauthenticated request to a protected WebSphere endpoint. The flaw disables the normal authentication check, enabling the attacker to access resources or administrative interfaces that should be restricted to authenticated users. This access control weakness (CWE‑862) permits unauthorized use of the application server, potentially exposing confidential data, altering configuration, or enabling denial of service.

Affected Systems

Vendors affected are IBM WebSphere Application Server, versions 8.5.0.0 through 8.5.5.30 and 9.0.0.0 through 9.0.5.28. The advisory specifically lists all installations within these version ranges as vulnerable, requiring remediation by applying the interim fix for APAR DT496677 or upgrading to the targeted fix pack levels (8.5.5.31 or later, 9.0.5.29 or later).

Risk and Exploitability

The CVSS score of 7 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation at the present time. The vulnerability has not been listed in the CISA KEV catalog. Exploitation would occur via a remote crafted request to the application server; any network‑connected attacker who can reach the WebSphere endpoint could trigger the authentication bypass, especially if the server is exposed to untrusted networks.

Generated by OpenCVE AI on August 4, 2026 at 12:50 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR DT496677. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496677 https://www.ibm.com/support/pages/node/7281577 --OR-- · Apply Fix Pack 9.0.5.29 or later (targeted availability 3Q2026).  For V8.5.0.0 through 8.5.5.30: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves DT496677 https://www.ibm.com/support/pages/node/7281577 --OR-- · Apply Fix Pack 8.5.5.31 or later (targeted availability 3Q2026).  Additional interim fixes may be available and linked off the interim fix download page.


OpenCVE Recommended Actions

  • Apply the IBM interim fix for APAR DT496677 immediately.
  • If the interim fix is not yet available, upgrade to the minimal required fix pack level for your WebSphere version and then apply the interim fix.
  • Once released, update to Fix Pack 9.0.5.29 or later (or 8.5.5.31 or later) to receive the permanent fix.
  • If the interim fix is not immediately available, consider temporarily restricting access to administrative interfaces via network segmentation or additional authentication (inferred).

Generated by OpenCVE AI on August 4, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
Title IBM WebSphere Application Server is affected by an authentication bypass
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-862
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-29T12:38:48.001Z

Reserved: 2026-07-18T00:53:31.768Z

Link: CVE-2026-16184

cve-icon Vulnrichment

Updated: 2026-07-29T12:38:43.003Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T20:17:23.330

Modified: 2026-08-03T14:55:49.547

Link: CVE-2026-16184

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:00:11Z

Weaknesses