ibm websphere-application-server CVE-2026-16187 is a vulnerability in IBM WebSphere Application Server
Published on September 14, 2026

IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
NONE
Availability Impact:
NONE

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-16187 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-16187

Want to know whenever a new CVE is published for IBM WebSphere Application Server? stack.watch will email you.

 

Affected Versions

IBM WebSphere Application Server: