Description
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.
Published: 2026-09-14
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Immediate Patch
AI Analysis

Impact

IBM WebSphere Application Server 8.5 and 9.0 are vulnerable to an authorization bypass, allowing an attacker to gain elevated privileges within the application. The flaw is identified as CWE-862 and can lead to unauthorized access to protected resources, potentially impacting the confidentiality and integrity of data.

Affected Systems

The vulnerability affects IBM WebSphere Application Server versions 8.5.x up to 8.5.5.30 and 9.0.x up to 9.0.5.28. The vendor recommends applying Fix Pack 8.5.5.31 for 8.5 and Fix Pack 9.0.5.29 or later for 9.0, regardless of deployment environment.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector would involve an attacker with some level of access to the application to exploit the authorization flaw. Although no remote exploitation path is explicitly described, the potential for privilege escalation remains, warranting timely patching.

Generated by OpenCVE AI on September 15, 2026 at 11:56 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply IBM WebSphere Application Server Fix Pack 9.0.5.29 or later
  • Apply IBM WebSphere Application Server Fix Pack 8.5.5.31 or later
  • Review and enforce strict role‑based access controls to mitigate potential privilege escalation

Generated by OpenCVE AI on September 15, 2026 at 11:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-862
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T19:51:47.240Z

Reserved: 2026-07-18T01:53:47.588Z

Link: CVE-2026-16190

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:40.143

Modified: 2026-09-14T20:16:40.143

Link: CVE-2026-16190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T12:00:16Z

Weaknesses