Remote Code Execution Vulnerability in IBM WebSphere Application Server
CVE-2026-9311

9CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
1 June 2026

What is CVE-2026-9311?

IBM WebSphere Application Server versions 9.0 and 8.5 are exposed to a vulnerability that allows remote code execution due to inadequate bypass of established security controls. This exploitation can allow attackers to execute arbitrary code in the context of the running application, posing significant risks to data integrity and system functionality. Organizations using these versions should review the vendor advisory for recommendations on mitigating this risk.

Affected Version(s)

WebSphere Application Server 9.0 <= 1.1.9.12

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.