Junglewise Threat Intelligence

CVE-2026-11549: IBM WebSphere Application Server virtual host bypass

CVE-2026-11549 · Severity: medium · CVSS 6.5 · Published 2026-09-18

Technologies: IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server and WebSphere Application Server Liberty contain a virtual host bypass vulnerability that could allow attackers to circumvent security controls on application servers. This could result in unauthorized access to applications or data that should be restricted to specific virtual hosts.

Technical details

The vulnerability is a virtual host bypass flaw in IBM WebSphere Application Server and Liberty that allows attackers to bypass virtual host restrictions. The attack is network-accessible and likely requires crafted requests to circumvent hostname-based access controls. A patch or update is available from IBM.

Affected products

  • IBM WebSphere Application Server
  • IBM WebSphere Application Server Liberty

Timeline

  • 2026-09-18: disclosed

References

Related threats