Junglewise Threat Intelligence

CVE-2026-10852: IBM WebSphere Application Server denial of service in WebServer Plug-in

CVE-2026-10852 · Severity: medium · CVSS 5.9 · Published 2026-06-22

Technologies: IBM I, IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server and IBM i systems are vulnerable to a denial of service attack. This software is used to host and manage enterprise web applications. An attacker can send specifically crafted web requests that cause the server's web plug-in to crash, potentially leading to application downtime and service interruptions for users.

Technical details

A NULL pointer dereference (CWE-476) exists in the WebSphere WebServer Plug-in component used by IBM i, WebSphere Application Server, and WebSphere Application Server Liberty. The vulnerability is triggered when the plug-in processes a specially crafted HTTP request. While the attack vector is network-based and requires no authentication, the attack complexity is rated as high. Successful exploitation allows an unauthenticated remote attacker to cause a denial of service (crash) of the web server component. IBM has released Program Temporary Fixes (PTFs) for affected IBM i versions to remediate this issue.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6
  • IBM WebSphere Application Server 8.5, 9.0
  • IBM WebSphere Application Server Liberty All versions

Timeline

  • 2026-06-22: disclosed
  • 2026-06-22: advisory
  • 2026-06-22: patched

References

Related threats