Identity Spoofing Vulnerability in IBM WebSphere Application Server Liberty
CVE-2026-3621

7.5HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
22 April 2026

What is CVE-2026-3621?

IBM WebSphere Application Server Liberty is susceptible to identity spoofing when deployed with insufficient authentication and authorization configurations. This vulnerability arises under specific conditions, allowing unauthorized users to masquerade as legitimate identity holders, potentially leading to unauthorized access to sensitive resources.

Affected Version(s)

WebSphere Application Server - Liberty 17.0.0.3 <= 26.0.0.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.