Unauthorized Access Risk in IBM WebSphere Application Server
CVE-2026-11545

3.7LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2026-11545?

IBM WebSphere Application Server versions 8.5 and 9.0 contain a security flaw that could enable a remote attacker to gain unauthorized access to sensitive information stored in the administrative console. This vulnerability arises from inadequate authorization controls, which fail to properly restrict access, thereby exposing critical data to potential exploitation. Organizations utilizing these affected versions should prioritize the implementation of security patches provided by IBM to mitigate the risks associated with this vulnerability.

Affected Version(s)

WebSphere Application Server 8.5

WebSphere Application Server 9.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.