Log Injection Vulnerability in IBM WebSphere Application Server Products
CVE-2026-11538

3.7LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2026-11538?

IBM WebSphere Application Server versions 9.0 and 8.5 are vulnerable to a log injection issue that arises from the handling of crafted LTPA token cookies. This vulnerability may allow an attacker to inject malicious log data, potentially compromising the integrity of application logs and leading to further exploitation or data leakage. It is crucial for users of these versions to apply the necessary security patches and take preventive measures to mitigate this risk.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.