CVE-2026-9327
moderateImproper Privilege Management in IBM WebSphere Application Server 8.5 and 9.0
IBM WebSphere Application Server 8.5 and 9.0 suffer from an improper privilege management flaw (CWE-269) in which an authenticated user holding a low-privilege administrative role can modify the server's security configuration. The flaw is triggered through normal administrative access to the WebSphere administrative console or related admin interfaces, after valid authentication. A successful attacker can abuse this to expose sensitive information or cause denial of service, reflected in the CVSS 3.1 base score of 8.1 (high) with high confidentiality and availability impact. Any deployment of WebSphere Application Server 8.5 or 9.0 that grants administrative roles beyond fully trusted operators is affected. There is no known public proof of concept, the CVE is not on the CISA KEV list, and no in-the-wild exploitation has been reported.
What to do: Apply IBM's fix for this vulnerability (latest fix pack/interim fix per the IBM security bulletin) to all WebSphere Application Server 8.5 and 9.0 deployments. Restrict administrative console access to trusted networks and limit assignment of low-privilege administrative roles to only necessary users. Audit existing admin role assignments and review security configuration change logs for unauthorized modifications.
| IBM WebSphere Application Server | 9.0, 8.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
- Vendors
- ibm
- Products
- websphere application server
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.