Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.
Published: 2026-09-10
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

IBM WebSphere Application Server versions 9.0 and 8.5 prior to fix packs 9.0.5.29 and 8.5.5.31 contain a security bypass caused by improper authentication controls. The flaw allows a local attacker to elevate privileges and gain unauthorized access to protected resources. The issue is identified as CWE‑94.

Affected Systems

Affected products include IBM WebSphere Application Server 9.0 and 8.5 across all sub‑versions that have not received the listed fix packs. The specific vulnerable versions are 9.0.x up to 9.0.5.28 and 8.5.x up to 8.5.5.30. Security patches are provided in Fix Pack 9.0.5.29 (SB0030823) and Fix Pack 8.5.5.31, respectively; any later fix pack also contains the remediation.

Risk and Exploitability

The CVSS score of 6.7 indicates that the vulnerability is of moderate severity. Existing exploitation data for this flaw is not available, and it is not currently listed in the CISA KEV catalog. Because the attack requires local access and the attacker must have some presence on the system, the likelihood of exploitation is considered moderate. The flaw’s exploitation path involves an authenticated session escalation, so protection measures such as proper authentication handling and least‑privilege enforcement are essential.

Generated by OpenCVE AI on September 11, 2026 at 04:52 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by applying the fix pack(s) listed below. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Apply Fix Pack 9.0.5.29 SB0030823 (availability September 2026) or later fix pack.  For V8.5.0.0 through 8.5.5.30: · Apply Fix Pack 8.5.5.31 https://www.ibm.com/support/pages/node/7285869 (availability September 2026) or later fix pack.


OpenCVE Recommended Actions

  • Apply Fix Pack 9.0.5.29 or a9.0.x
  • Apply Fix Pack 8.5.5.31 or a later fix pack to WebSphere Application Server 8.5.x
  • Re‑configure authentication schemes to enforce strict credential validation and disable any default or unused privileged accounts

Generated by OpenCVE AI on September 11, 2026 at 04:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.
Title IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
First Time appeared Ibm
Ibm websphere Application Server
Weaknesses CWE-94
CPEs cpe:2.3:a:ibm:websphere_application_server:8.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm websphere Application Server
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Websphere Application Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T20:45:57.913Z

Reserved: 2026-05-21T14:41:00.465Z

Link: CVE-2026-9176

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T21:17:54.220

Modified: 2026-09-10T21:34:14.253

Link: CVE-2026-9176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:30:07Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')