Authentication Bypass Vulnerability in IBM WebSphere Application Server
CVE-2026-16184

7HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
28 July 2026

What is CVE-2026-16184?

IBM WebSphere Application Server versions 9.0 and 8.5 are susceptible to an authentication bypass vulnerability. A remote attacker could exploit this flaw by sending a specially crafted unauthenticated request, potentially allowing unauthorized access to sensitive components of the application server. Organizations using these affected versions should take immediate steps to mitigate the risk by applying available patches and reviewing their security protocols.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.