CVE-2026-9176
moderateLocal Privilege Escalation via Authentication Bypass in IBM WebSphere Application Server
IBM WebSphere Application Server 8.5 and 9.0 contain a security bypass flaw caused by improper authentication controls, formally classified under CWE-94. A local attacker who already has some level of access to the host can exploit the weak authentication logic to escalate privileges and gain unauthorized access to protected resources, with high impact on both confidentiality and integrity (availability is not affected). Because the attack vector is local and requires low privileges, the attacker must first have a foothold on the server, which limits remote exploitation risk. Affected organizations are those running the 8.5 or 9.0 releases of WebSphere Application Server, typically enterprise middleware deployments. No public proof-of-concept exists, the flaw is not on the CISA KEV catalog, and no exploitation in the wild is currently known.
What to do: Apply the fix pack or interim fix IBM specifies in its security bulletin for WebSphere Application Server 8.5 and 9.0 as soon as it is available. Since exploitation requires local access with low privileges, restrict OS-level accounts on WAS hosts, enforce least-privilege for service and administrative accounts, and review local authentication and group membership for unexpected changes. Monitor logs for signs of privilege escalation or access to protected resources by low-privileged accounts.
| IBM WebSphere Application Server | 9.0, 8.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.
- Vendors
- ibm
- Products
- websphere application server
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.