ibm websphere-application-server CVE-2026-16190 is a vulnerability in IBM WebSphere Application Server
Published on September 14, 2026

IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
NONE
Availability Impact:
NONE

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-16190 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-16190

Want to know whenever a new CVE is published for IBM WebSphere Application Server? stack.watch will email you.

 

Affected Versions

IBM WebSphere Application Server: