CVE-2026-16184: IBM WebSphere Application Server is affected by an authentication bypass
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
Other sources
IBM WebSphere Application Server could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.31Patch APAR DT496677 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29Patch APAR DT496677
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16184?
The severity of CVE-2026-16184 is classified as high with a score of 7.
How do I fix CVE-2026-16184?
To fix CVE-2026-16184, update IBM WebSphere Application Server to the latest version that addresses the authentication bypass vulnerability.
What systems are affected by CVE-2026-16184?
CVE-2026-16184 affects IBM WebSphere Application Server versions 9.0 and 8.5.
How does CVE-2026-16184 allow unauthorized access?
CVE-2026-16184 allows a remote attacker to bypass authentication by sending a crafted unauthenticated request.
What are the potential risks of CVE-2026-16184?
The potential risks of CVE-2026-16184 include unauthorized access to sensitive data and potential system compromise.