Log Injection Vulnerability in IBM WebSphere Application Server
CVE-2026-16189

4.8MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 September 2026

What is CVE-2026-16189?

IBM WebSphere Application Server versions 9.0 and 8.5 are susceptible to a log injection vulnerability that enables an unauthorized remote attacker to manipulate administrative log entries. This could potentially compromise the integrity of the log data, making it harder for administrators to track legitimate activity and identify malicious actions. By exploiting this weakness, attackers may misrepresent system activities, which could lead to severe security repercussions if not addressed promptly. Administrators are advised to implement the recommended patches from IBM to mitigate this risk.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.