CVE-2026-16190 is a vulnerability in IBM WebSphere Application Server
Published on September 14, 2026
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.
Vulnerability Analysis
Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
NONE
Availability Impact:
NONE
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-16190 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-16190
Want to know whenever a new CVE is published for IBM WebSphere Application Server? stack.watch will email you.
Affected Versions
IBM WebSphere Application Server:- Version 9.0 is affected.
- Version 8.5 is affected.