CVE-2026-10842: IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.
Other sources
IBM WebSphere Application Server Traditional and Liberty could allow a remote attacker to bypass security constraints.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server Libertyto a version that resolves this vulnerability.Fixed in 26.0.0.8 - Upgrade
Upgrade
IBM WebSphere Application Server Traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server Traditionalto a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71893 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71916
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10842?
The severity of CVE-2026-10842 is rated as high with a CVSS score of 7.5.
How do I fix CVE-2026-10842?
To fix CVE-2026-10842, upgrade to the latest versions of IBM WebSphere Application Server and WebSphere Application Server Liberty that address this vulnerability.
What systems are affected by CVE-2026-10842?
CVE-2026-10842 affects IBM WebSphere Application Server versions 8.5 and 9.0, and IBM WebSphere Liberty versions 17.0.0.3 through 26.0.0.7.
What type of vulnerability is CVE-2026-10842?
CVE-2026-10842 is a security bypass vulnerability that could allow a remote attacker to bypass security constraints.
What is the potential impact of CVE-2026-10842?
The potential impact of CVE-2026-10842 includes unauthorized access to sensitive data due to bypassing security measures.