IBM WebSphere AppServer 8.5-9.0: Low-Priv Auth Admin Mod Config for Info Leak/DoS
CVE-2026-9327 Published on September 10, 2026
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.
Vulnerability Analysis
CVE-2026-9327 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
Improper Privilege Management
The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Products Associated with CVE-2026-9327
Want to know whenever a new CVE is published for IBM WebSphere Application Server? stack.watch will email you.
Affected Versions
IBM WebSphere Application Server:- Version 9.0 is affected.
- Version 8.5 is affected.