Junglewise Threat Intelligence

CVE-2026-9072: IBM WebSphere WebServer Plug-in code injection in Intelligent Management

CVE-2026-9072 · Severity: high · CVSS 8.1 · Published 2026-06-22

Technologies: IBM I, IBM WebSphere Application Server Liberty, IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM i and WebSphere Application Server are affected by a security vulnerability in the Intelligent Management component of the WebServer Plug-in. An attacker who can impersonate a backend server could send malicious responses that allow them to take control of the system or cause a service outage. This could lead to unauthorized access to sensitive business data or significant operational downtime.

Technical details

The vulnerability is classified as Improper Control of Generation of Code (CWE-94) within the Intelligent Management feature of the IBM WebSphere WebServer Plug-in. It occurs when the plug-in processes responses from backend servers without sufficient validation. An attacker capable of intercepting or spoofing backend server communications (network-based attack vector) can send crafted responses to trigger remote code execution or a denial of service state. While the attack requires a high complexity (AC:H) to successfully impersonate a backend server, it requires no authentication or user interaction. IBM has released PTFs for affected IBM i versions (7.3 through 7.6) to remediate the issue.

Affected products

  • IBM i 7.3, 7.4, 7.5, 7.6
  • IBM WebSphere Application Server 8.5, 9.0
  • IBM WebSphere Application Server Liberty All versions using Intelligent Management with WebServer Plug-in

Timeline

  • 2026-06-22: disclosed
  • 2026-06-22: patched
  • 2026-06-22: advisory

References

Related threats