Cross-Site Scripting Vulnerability in IBM WebSphere Application Server
CVE-2026-11708

9.3CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 June 2026

What is CVE-2026-11708?

The IBM WebSphere Application Server versions 8.5 and 9.0 have a vulnerability that allows attackers to exploit the administrative console's integrated help system through cross-site scripting. This flaw could enable unauthorized users to inject malicious scripts that can manipulate user interactions with the console. It's crucial for administrators to assess their setups and apply recommended patches to mitigate potential security risks.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.