CVE-2026-10845: IBM WebSphere Application Server is affected by an authentication bypass vulnerability
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Serverto a version that resolves this vulnerability.Fixed in 8.5.5.30 - Upgrade
Upgrade
IBM WebSphere Application Serverto a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade
IBM WebSphere Application Serverto a version that resolves this vulnerability.Patch PH71648
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10845?
CVE-2026-10845 has a high severity rating of 7.3 on the CVSS scale.
How do I fix CVE-2026-10845?
To mitigate CVE-2026-10845, apply the latest security patches provided by IBM for WebSphere Application Server.
What applications are affected by CVE-2026-10845?
CVE-2026-10845 affects JAX-WS applications running on IBM WebSphere Application Server 8.5 and 9.0.
Can CVE-2026-10845 be exploited remotely?
Yes, CVE-2026-10845 can be exploited by remote attackers to bypass authentication.
What is the impact of CVE-2026-10845?
The impact of CVE-2026-10845 includes unauthorized access to JAX-WS applications in IBM WebSphere Application Server.