CVE-2026-8644
Analyzed Analyzed - Analysis Complete
Identity Spoofing in IBM WebSphere Application Server

Publication date: 2026-06-01

Last updated on: 2026-06-04

Assigner: IBM Corporation

Description
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-01
Last Modified
2026-06-04
Generated
2026-06-22
AI Q&A
2026-06-01
EPSS Evaluated
2026-06-20
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
ibm websphere_application_server From 8.5.0.0 (inc) to 8.5.5.30 (exc)
ibm websphere_application_server From 9.0.0.0 (inc) to 9.0.5.29 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

The identity spoofing vulnerability in IBM WebSphere Application Server allows attackers to bypass authentication mechanisms and potentially gain unauthorized access to the system.

Such unauthorized access can lead to exposure or manipulation of sensitive data, which may result in non-compliance with data protection regulations and standards like GDPR and HIPAA that require strict access controls and protection of personal and health information.

Therefore, this vulnerability poses a significant risk to compliance with these regulations if not promptly addressed.

Executive Summary

CVE-2026-8644 is an identity spoofing vulnerability in IBM WebSphere Application Server versions 9.0 and 8.5.

This vulnerability allows attackers to bypass authentication mechanisms, effectively impersonating legitimate users or identities.

It is classified under CWE-290 (Authentication Bypass by Spoofing) and has a critical severity with a CVSS base score of 9.1.

Impact Analysis

The vulnerability can allow attackers to gain unauthorized access to the system by bypassing authentication.

This unauthorized access can lead to high impact on integrity and availability of the system, as indicated by the CVSS vector (I:H/A:H).

Attackers could potentially manipulate data or disrupt services within the affected IBM WebSphere Application Server environment.

Mitigation Strategies

IBM recommends applying an interim fix for APAR PH71422 or upgrading to specific fix packs to address the vulnerability.

  • For IBM WebSphere Application Server version 9.0.0.0 through 9.0.5.28, apply the interim fix or upgrade to Fix Pack 9.0.5.29 or later.
  • For version 8.5.0.0 through 8.5.5.29, apply the interim fix or upgrade to Fix Pack 8.5.5.30 or later.

No workarounds or mitigations are currently available, so applying the fixes or upgrades is the immediate recommended action.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8644. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart