IBM WebSphere App Server 8.5-9.0 DoS via Admin HTTP Endpoint
CVE-2026-9336 Published on September 10, 2026
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.
Vulnerability Analysis
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-9336
Want to know whenever a new CVE is published for IBM WebSphere Application Server? stack.watch will email you.
Affected Versions
IBM WebSphere Application Server:- Version 9.0 is affected.
- Version 8.5 is affected.