Junglewise Threat Intelligence

CVE-2026-8644: IBM WebSphere Application Server identity spoofing authentication bypass

CVE-2026-8644 · Severity: critical · CVSS 9.1 · Published 2026-06-01

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server, a platform used to host and run enterprise Java applications, is vulnerable to an identity spoofing flaw. This vulnerability allows an unauthenticated attacker to impersonate legitimate users or systems over the network. Successful exploitation could lead to unauthorized data modification or a significant disruption of business operations and services.

Technical details

IBM WebSphere Application Server is vulnerable to an authentication bypass via identity spoofing (CWE-290). The vulnerability exists in versions 9.0 (up to 9.0.5.28) and 8.5 (up to 8.5.5.29). An unauthenticated remote attacker can exploit this flaw over the network with low complexity and no user interaction required. Successful exploitation allows the attacker to spoof identities, potentially leading to high impacts on system integrity and availability. IBM has released interim fixes under APAR PH71422 and plans to include permanent fixes in Fix Packs 9.0.5.29 and 8.5.5.30.

Affected products

  • IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.29

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory
  • 2026-06-01: patched: Interim fix PH71422 released

References

Related threats