Junglewise Threat Intelligence

CVE-2026-11707: IBM WebSphere Application Server XSS in administrative console login page

CVE-2026-11707 · Severity: critical · CVSS 9.3 · Published 2026-07-30

Executive brief

IBM Tivoli System Automation Application Manager and WebSphere Application Server are affected by a security flaw in the administrative console's login page. This vulnerability could allow an attacker to trick a legitimate user into executing malicious code within their web browser. If successful, the attacker could potentially hijack the user's session, access sensitive administrative data, or perform unauthorized actions on the management platform.

Technical details

A cross-site scripting (XSS) vulnerability exists in the administrative console login page of IBM WebSphere Application Server, which is utilized by IBM Tivoli System Automation Application Manager. The flaw (CWE-79) is caused by improper neutralization of user-supplied input during web page generation. A remote, unauthenticated attacker can exploit this by persuading a user to visit a malicious URL or link, leading to the execution of arbitrary JavaScript in the victim's browser session. This can result in credential theft, session hijacking, or unauthorized administrative actions. The vulnerability affects WebSphere Application Server versions 8.5 and 9.0 as integrated with Tivoli System Automation Application Manager 4.1.

Affected products

  • IBM Tivoli System Automation Application Manager 4.1
  • IBM WebSphere Application Server 8.5, 9.0

Timeline

  • 2026-07-24: disclosed: Initial publication by IBM
  • 2026-07-30: advisory: NVD publication date

References

Related threats