Executive brief
IBM WebSphere Application Server is a popular Java-based middleware platform used to run enterprise applications. This vulnerability allows attackers with local system access to bypass authentication controls and gain unauthorized access to protected resources and sensitive functionality. Exploitation could lead to privilege escalation, unauthorized data access, or system compromise.
Technical details
CVE-2026-9176 is an authentication bypass vulnerability in IBM WebSphere Application Server 8.5 and 9.0 caused by improper authentication controls. The vulnerability requires local access to the target system and allows an attacker to escalate privileges and access protected resources that would normally require valid credentials. The IBM security bulletin indicates that patched versions 9.0.5.29 and 8.5.5.31 or later resolve this and related vulnerabilities. Affected users should upgrade to the fixed versions to remediate the issue.
Affected products
- IBM WebSphere Application Server 8.5 before 8.5.5.31, 9.0 before 9.0.5.29
Timeline
- 2026-09-10: disclosed