Cross-Site Scripting Vulnerability in IBM WebSphere Application Server
CVE-2026-11594

8.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 June 2026

What is CVE-2026-11594?

IBM WebSphere Application Server versions 9.0 and 8.5 contain a cross-site scripting vulnerability in the administrative console, which could allow attackers to execute arbitrary scripts in the context of a user's session. This could lead to unauthorized access or manipulation of data. It is highly recommended for users to apply security patches and updates as provided by IBM to mitigate potential risks.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.