IBM WebSphere AppServer 8.5-9.0: Low-Priv Auth Admin Mod Config for Info Leak/DoS
CVE-2026-9327 Published on September 10, 2026

IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-9327 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
HIGH

Weakness Type

Improper Privilege Management

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2026-9327

Want to know whenever a new CVE is published for IBM WebSphere Application Server? stack.watch will email you.

 

Affected Versions

IBM WebSphere Application Server: