Junglewise Threat Intelligence

CVE-2026-16185: IBM WebSphere Application Server authentication bypass in admin console servlet

CVE-2026-16185 · Severity: medium · CVSS 6.4 · Published 2026-09-14

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server is a Java-based application server used to host and run enterprise web applications. A vulnerability in its administrative console allows a remote attacker to bypass authentication controls, potentially granting unauthorized access to critical server administration functions.

Technical details

CVE-2026-16185 is an authentication bypass vulnerability (CWE-862: Missing Authorization) affecting the admin console servlet in IBM WebSphere Application Server. The vulnerability requires adjacent network access and specific conditions (AC:H), but allows an unauthenticated attacker to gain access without valid credentials. An attacker can exploit this to access sensitive administrative functions, potentially leading to information disclosure, configuration changes, and service disruption. Patches are available in versions 9.0.5.29 and later, and 8.5.5.31 and later.

Affected products

  • IBM WebSphere Application Server 8.5 before 8.5.5.31, 9.0 before 9.0.5.29

Timeline

  • 2026-09-14: disclosed

References

Related threats