Junglewise Threat Intelligence

CVE-2026-11539: IBM WebSphere Application Server authentication bypass in SOAP/JMX connector

CVE-2026-11539 · Severity: medium · CVSS 5.3 · Published 2026-09-18

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server is a Java-based middleware platform that runs enterprise applications. An authentication bypass vulnerability in the SOAP/JMX connector could allow an attacker to gain unauthorized administrative access to the server without valid credentials, potentially compromising the entire application environment and exposing sensitive data.

Technical details

The SOAP/JMX connector in IBM WebSphere Application Server 8.5 and 9.0 fails to properly validate authentication credentials, allowing unauthenticated remote attackers to bypass access controls via crafted SOAP requests. This enables unauthorized access to JMX management interfaces without requiring valid administrative credentials. The vulnerability is fixed in versions 8.5.5.31 and 9.0.5.29 and later.

Affected products

  • IBM WebSphere Application Server 8.5 prior to 8.5.5.31, 9.0 prior to 9.0.5.29

Timeline

  • 2026-09-18: disclosed

References

Related threats