CVE-2026-11539: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
Published Sep 8, 2026
·Updated
IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.
Other sources
IBM WebSphere Application Server is affected by an authentication bypass vulnerability in the SOAP/JMX connector.
— IBM
Affected Software
2 affected components
IBM WebSphere Application Server<=9.0
IBM WebSphere Application Server<=8.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional (8.5) SOAP/JMX connectorto a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditional (9.0) SOAP/JMX connectorto a version that resolves this vulnerability.Fixed in 9.0.5.29Patch SB0030823
Event History
Sep 8, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 18, 2026
CVE Published
via MITRE·07:03 PM
Data Sourced
via MITRE·07:03 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness