Junglewise Threat Intelligence

CVE-2026-11712: IBM WebSphere Application Server XSS in administrative console help system

CVE-2026-11712 · Severity: critical · CVSS 9.3 · Published 2026-06-30

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server, a platform used to host and manage enterprise Java applications, contains a security flaw in its administrative console's help system. An attacker could use this vulnerability to execute malicious scripts in the browser of an administrative user who clicks a specially crafted link. This could lead to unauthorized actions being performed with the administrator's privileges, potentially compromising the entire application server environment.

Technical details

IBM WebSphere Application Server is vulnerable to a Cross-Site Scripting (XSS) attack (CWE-79) within the integrated help system of the administrative console. The vulnerability is caused by improper neutralization of user-supplied input during web page generation. A remote, unauthenticated attacker can exploit this by persuading a user (typically an administrator) to visit a malicious URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking or unauthorized administrative actions. IBM has released interim fix PH71756 to address this issue.

Affected products

  • IBM WebSphere Application Server 9.0.0.0 through 9.0.5.28, 8.5.0.0 through 8.5.5.30

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats