Junglewise Threat Intelligence

CVE-2026-10842: IBM WebSphere Application Server security bypass in appSecurity feature

CVE-2026-10842 · Severity: high · CVSS 7.5 · Published 2026-07-30

Executive brief

IBM WebSphere Application Server, a platform used to build and run enterprise applications, is affected by a security flaw that could allow unauthorized users to bypass access controls. By exploiting this vulnerability, a remote attacker could gain access to sensitive information or restricted areas of the application without proper authentication. This could lead to data exposure and unauthorized access to corporate systems.

Technical details

An authentication bypass vulnerability (CWE-289: Authentication Bypass by Alternate Name) exists in IBM WebSphere Application Server Traditional and Liberty. The flaw is present when specific application security features (appSecurity-1.0 through 4.0) are enabled. A remote, unauthenticated attacker can exploit this vulnerability over the network to bypass security constraints and gain unauthorized access to protected resources. The root cause involves improper validation of identity during the authentication process. IBM has released interim fixes (PH71893 and PH71916) and plans to include permanent fixes in upcoming Fix Packs (9.0.5.29, 8.5.5.31, and 26.0.0.8).

Affected products

  • IBM WebSphere Application Server 8.5.0.0 - 8.5.5.30, 9.0.0.0 - 9.0.5.28
  • IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.7

Timeline

  • 2026-07-15: advisory: Initial publication by IBM
  • 2026-07-30: disclosed: NVD publication date

References

Related threats