Executive brief
IBM WebSphere Application Server is a Java-based application server used to host enterprise web applications. CVE-2026-16187 allows a remote attacker to bypass authentication and access sensitive information by sending a specially crafted unauthenticated request, potentially compromising administrative access and exposing confidential business data.
Technical details
This vulnerability is an authentication bypass affecting the admin console servlet in IBM WebSphere Application Server versions 8.5 and 9.0 (fixed in 8.5.5.31 and 9.0.5.29). The vulnerability allows a remote attacker to craft a request that bypasses authentication controls without requiring valid credentials. Attack vectors are network-based and no prior authentication or user interaction is required. A successful exploit grants unauthorized access to sensitive information and administrative functions, potentially leading to full system compromise.
Affected products
- IBM WebSphere Application Server 8.5 prior to 8.5.5.31, 9.0 prior to 9.0.5.29
Timeline
- 2026-09-14: disclosed