CVE-2026-10845
Undergoing Analysis Undergoing Analysis - In Progress
Authentication Bypass in IBM WebSphere Application Server

Publication date: 2026-06-22

Last updated on: 2026-06-22

Assigner: IBM Corporation

Description
IBM WebSphere Application Server 8.5 and 9.0Β could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-22
Last Modified
2026-06-22
Generated
2026-06-22
AI Q&A
2026-06-22
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
ibm websphere_application_server 8.5
ibm websphere_application_server 9.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects IBM WebSphere Application Server versions 8.5 and 9.0. It allows a remote attacker to bypass authentication mechanisms and gain unauthorized access specifically to JAX-WS applications hosted on the server.

The issue is classified under CWE-287, which relates to improper authentication, meaning the system fails to properly verify the identity of users or requests.

Impact Analysis

An attacker exploiting this vulnerability can bypass authentication controls and gain unauthorized access to JAX-WS applications running on IBM WebSphere Application Server. This could lead to exposure of sensitive data, unauthorized operations, or further compromise of the affected system.

Given the high severity score of 7.5, the impact is significant and could affect the confidentiality, integrity, and availability of the applications and data.

Mitigation Strategies

IBM recommends applying interim fixes or upgrading to specific fix packs to address the vulnerability in IBM WebSphere Application Server 8.5 and 9.0.

No workarounds are currently available, so applying the provided fixes as soon as they are released is the primary mitigation step.

Compliance Impact

The vulnerability allows a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications in IBM WebSphere Application Server versions 8.5 and 9.0.

Such unauthorized access could potentially lead to exposure or compromise of sensitive data, which may impact compliance with common standards and regulations like GDPR and HIPAA that require strict access controls and protection of personal or health information.

However, the provided information does not explicitly describe the direct impact on compliance with these regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10845. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart