ibm websphere-application-server CVE-2026-16185 is a vulnerability in IBM WebSphere Application Server
Published on September 14, 2026

IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
HIGH

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-16185 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-16185

Want to know whenever a new CVE is published for IBM WebSphere Application Server? stack.watch will email you.

 

Affected Versions

IBM WebSphere Application Server: