CVE-2026-9320
Undergoing Analysis Undergoing Analysis - In Progress
Denial of Service in IBM WebSphere Application Server

Publication date: 2026-06-22

Last updated on: 2026-06-22

Assigner: IBM Corporation

Description
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-22
Last Modified
2026-06-22
Generated
2026-06-22
AI Q&A
2026-06-22
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
ibm websphere_application_server 9.0
ibm websphere_application_server 8.5
ibm websphere_application_server_liberty to 26.0.0.6 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects IBM WebSphere Application Server versions 9.0, 8.5, and IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.6. It is caused by sending a specially-crafted request to the server.

A remote attacker can exploit this vulnerability to cause the server to consume excessive memory resources, leading to a denial of service condition.

Impact Analysis

Exploitation of this vulnerability can cause the affected IBM WebSphere Application Server to consume excessive memory resources.

This can result in a denial of service (DoS), where legitimate users may be unable to access the server or its services due to resource exhaustion.

Compliance Impact

The provided information does not specify how the denial of service vulnerability in IBM WebSphere Application Server (CVE-2026-9320) impacts compliance with common standards and regulations such as GDPR or HIPAA.

Mitigation Strategies

The CVE description indicates that the vulnerability is caused by sending a specially-crafted request that leads to denial of service by consuming memory resources on IBM WebSphere Application Server versions 8.5, 9.0, and Liberty 17.0.0.3 through 26.0.0.6.

No specific mitigation steps or workarounds are provided in the given resources for CVE-2026-9320.

Based on typical best practices for such vulnerabilities, immediate steps would generally include monitoring and restricting incoming requests to prevent malformed or suspicious traffic, applying any available patches or updates from IBM once released, and considering temporary network-level protections such as rate limiting or firewall rules to reduce exposure.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9320. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart