Description
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.
Published: 2026-09-14
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass on the admin console
Action: Apply Patch
AI Analysis

Impact

IBM WebSphere Application Server versions prior to 9.0.5.29 for the 9.0.x line and prior to 8.5.5.31 for the 8.5.x line contain a weakness that allows a remote attacker to bypass authentication on an admin console servlet. The vulnerability enables an attacker to gain access to administrative functions without proper credentials, as specified in the vendor’s advisory.

Affected Systems

The affected products are IBM WebSphere Application Server 8.5.x and 9.0.x. Specifically, any release before 8.5.5.31 in the 8.5.x series or before 9.0.5.29 in the 9.0.x series is vulnerable. The official fix packs are 8.5.5.31 or newer for WebSphere 8.5.x and 9.0.5.29 or newer for WebSphere 9.x.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity. The EPSS score of 0.00204, less than 1%, suggests a very low probability of exploitation. The vulnerability is described as a remote authentication bypass, implying that an attacker who can reach the admin console over the network could potentially use the flaw. The vulnerability is not listed in the CISA KEV catalog, indicating no known active, widespread exploitation.

Generated by OpenCVE AI on September 20, 2026 at 22:22 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply IBM Fix Pack 9.0.5.29 or later for WebSphere 9.x and 8.5.5.31 or later for WebSphere 8.5.x as advised by IBM.
  • Restrict external access to the admin console servlet with firewall rules or network segmentation until the patch is in place.
  • Enforce strong, unique credentials for all administrative accounts and disable any default or unused admin accounts.

Generated by OpenCVE AI on September 20, 2026 at 22:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-862
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T20:13:30.131Z

Reserved: 2026-07-18T01:44:43.845Z

Link: CVE-2026-16185

cve-icon Vulnrichment

Updated: 2026-09-14T20:13:02.214Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:39.500

Modified: 2026-09-16T19:22:22.797

Link: CVE-2026-16185

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:30:06Z

Weaknesses