Junglewise Threat Intelligence

CVE-2026-8858: IBM WebSphere Web Server Plug-in remote code execution

CVE-2026-8858 · Severity: high · CVSS 7.5 · Published 2026-06-22

Technologies: IBM I, IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM i and WebSphere Application Server are vulnerable to a security flaw in the component that connects web servers to application servers. An attacker who can impersonate an application server can send malicious responses to take control of the system or cause a service outage. This could lead to unauthorized access to corporate data or a total disruption of business applications running on these platforms.

Technical details

A code injection vulnerability (CWE-94) exists in the WebSphere Web Server Plug-in component used by IBM i and WebSphere Application Server. The flaw is triggered when the plug-in receives a specially crafted response from an entity impersonating a backend application server. An attacker with adjacent network access can exploit this to achieve remote code execution or cause a denial of service. The attack requires a high level of complexity to successfully impersonate the server. IBM has released PTFs (SJ10119, SJ10120, SJ10121, SJ10122) to address this issue across supported IBM i versions.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6
  • IBM WebSphere Application Server 8.5, 9.0
  • IBM WebSphere Application Server Liberty All versions

Timeline

  • 2026-06-22: disclosed
  • 2026-06-22: advisory
  • 2026-06-22: patched

References

Related threats