Vulnerability in IBM WebSphere Application Server Allows Unauthorized Configuration Modifications
CVE-2026-9327

6.3MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
10 September 2026

What is CVE-2026-9327?

An issue in IBM WebSphere Application Server versions 9.0 and 8.5 allows authenticated users with low-privilege administrative roles to alter security configurations. This vulnerability poses significant risks, including potential information disclosure and denial of service impacts, emphasizing the importance of restricting administrative privileges and applying necessary patches.

Affected Version(s)

WebSphere Application Server 9.0

WebSphere Application Server 8.5

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.