ZeroHour

CVE-2026-9327

moderate

Improper Privilege Management in IBM WebSphere Application Server 8.5 and 9.0

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

IBM WebSphere Application Server 8.5 and 9.0 suffer from an improper privilege management flaw (CWE-269) in which an authenticated user holding a low-privilege administrative role can modify the server's security configuration. The flaw is triggered through normal administrative access to the WebSphere administrative console or related admin interfaces, after valid authentication. A successful attacker can abuse this to expose sensitive information or cause denial of service, reflected in the CVSS 3.1 base score of 8.1 (high) with high confidentiality and availability impact. Any deployment of WebSphere Application Server 8.5 or 9.0 that grants administrative roles beyond fully trusted operators is affected. There is no known public proof of concept, the CVE is not on the CISA KEV list, and no in-the-wild exploitation has been reported.

What to do: Apply IBM's fix for this vulnerability (latest fix pack/interim fix per the IBM security bulletin) to all WebSphere Application Server 8.5 and 9.0 deployments. Restrict administrative console access to trusted networks and limit assignment of low-privilege administrative roles to only necessary users. Audit existing admin role assignments and review security configuration change logs for unauthorized modifications.

Affected
IBM WebSphere Application Server9.0, 8.5
Estimated exposure
moderate≈1,000s of internet-exposed admin endpoints; total enterprise install base likely in the tens of thousands (estimate) — WebSphere is a legacy enterprise product typically deployed on-premises, with public internet scans historically finding only a few thousand reachable admin consoles, plus an unknown but larger number of internal deployments.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.

Vendors
ibm
Products
websphere application server
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.