Executive brief
IBM WebSphere Application Server is an enterprise Java application platform used to run business-critical web applications. A flaw in the FileTransfer servlet could allow a remote attacker to obtain sensitive information about the server's file system without proper authentication, potentially exposing configuration files, credentials, or other confidential data.
Technical details
CVE-2026-11540 is an information disclosure vulnerability in the FileTransfer servlet component of WebSphere Application Server 8.5 and 9.0 prior to patched versions (8.5.5.31 and 9.0.5.29). The vulnerability allows unauthenticated or remote attackers to access file system information through improper access controls on the servlet endpoint. This is a network-accessible attack with no authentication required, exposing sensitive organizational data.
Affected products
- IBM WebSphere Application Server 8.5 before 8.5.5.31, 9.0 before 9.0.5.29
Timeline
- 2026-09-18: disclosed