Junglewise Threat Intelligence

CVE-2026-8646: IBM WebSphere Application Server HTTP request smuggling

CVE-2026-8646 · Severity: high · CVSS 7.4 · Published 2026-06-22

Technologies: IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server, a platform used to host and run enterprise Java applications, is vulnerable to a security flaw that allows attackers to manipulate how the server processes web requests. By sending specially crafted traffic, a remote attacker can bypass security filters, impersonate other users, or gain unauthorized access to sensitive information. This could lead to data breaches or unauthorized administrative actions within the hosted applications.

Technical details

IBM WebSphere Application Server (Traditional and Liberty) is vulnerable to HTTP request smuggling (CWE-444) due to inconsistent interpretation of HTTP requests. A remote, unauthenticated attacker can exploit this by sending specially crafted requests that are parsed differently by a front-end proxy and the back-end WebSphere server. Successful exploitation allows the attacker to 'smuggle' a hidden request, potentially leading to security control bypass, identity spoofing, privilege escalation, and unauthorized data exposure. For Liberty environments, the vulnerability specifically affects instances with servlet (3.0 through 6.1) or websocket (1.0 through 2.2) features enabled. Remediation involves applying interim fixes for APARs PH71631 and PH71370 or upgrading to fix packs 26.0.0.7, 9.0.5.29, or 8.5.5.30.

Affected products

  • IBM WebSphere Application Server 9.0.0.0 - 9.0.5.28, 8.5.0.0 - 8.5.5.29
  • IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.6

Timeline

  • 2026-06-16: advisory: Initial publication by IBM
  • 2026-06-22: disclosed: NVD publication date

References

Related threats