Description
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.
Published: 2026-09-14
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Patch Now
AI Analysis

Impact

IBM WebSphere Application Server 9.0 and 8.5 are vulnerable to an authentication bypass that occurs when a user accesses XD or Intelligent‑Management features. The flaw allows an unauthenticated user to obtain management‑level access, which can enable further exploitation of the application server. The weakness is classified as CWE‑650, indicating a flaw in the authentication control mechanisms.

Affected Systems

IBM WebSphere Application Server 8.5 and 9.0, all releases prior to 8.5.5.31 and 9.0.5.29, respectively, are affected. These versions expose XD or Intelligent‑Management interfaces until they are patched or the features are disabled.

Risk and Exploitability

The CVSS score of 5.9 reflects a moderate impact. EPSS is reported as < 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV, suggesting no known widespread attacks. Based on the description, the likely attack vector is a network‑based web request that targets the XD or Intelligent‑Management endpoints. If an attacker can reach these interfaces, the flaw can be abused to pass authentication checks and gain control of the server management interface.

Generated by OpenCVE AI on September 20, 2026 at 23:01 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply the IBM fix pack listed for your product version—9.0.5.29 SB0030823 or later for WebSphere Application Server 9.0, or 8.5.5.31 or later for WebSphere Application Server 8.5.
  • If XD or Intelligent‑Management features are not required, disable them in the server configuration to eliminate the attack surface.
  • Restrict network access to the XD or Intelligent‑Management interfaces using firewall rules or network segmentation, ensuring that only trusted internal hosts can reach the management ports.

Generated by OpenCVE AI on September 20, 2026 at 23:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-650
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T18:05:23.419Z

Reserved: 2026-07-21T02:53:33.021Z

Link: CVE-2026-16435

cve-icon Vulnrichment

Updated: 2026-09-15T17:38:50.636Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:40.790

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-16435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses
  • CWE-650

    Trusting HTTP Permission Methods on the Server Side