Junglewise Threat Intelligence

CVE-2026-9667: IBM WebSphere Application Server server-side request forgery

CVE-2026-9667 · Severity: medium · CVSS 5.3 · Published 2026-09-10

Technologies: IBM WebSphere Application Server. Vendors: IBM.

Executive brief

IBM WebSphere Application Server is a widely-used Java application platform that hosts enterprise business applications. An unauthenticated attacker can exploit a server-side request forgery (SSRF) flaw to trick the server into making outbound network requests to arbitrary endpoints. This could enable attackers to scan internal networks, access internal services, exfiltrate sensitive data, or launch further attacks against backend systems.

Technical details

This SSRF vulnerability (CVE-2026-9667) in IBM WebSphere Application Server 9.0 and 8.5 allows remote, unauthenticated attackers to cause the server to send arbitrary outbound HTTP requests. The vulnerability appears to stem from insufficient validation of user-controlled input used in server-side request operations. No authentication or special user interaction is required for exploitation; a direct network request to the vulnerable application is sufficient. An attacker can leverage this to probe internal network topology, access internal APIs or services, retrieve sensitive metadata, or interact with backend systems that trust the application server. Patches are available in versions 9.0.5.29 and 8.5.5.31 or later.

Affected products

  • IBM WebSphere Application Server 8.5, 9.0 (before 8.5.5.31 and 9.0.5.29)

Timeline

  • 2026-09-10: disclosed

References

Related threats