CVE-2026-16435: IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.
Other sources
IBM WebSphere Application Server is affected by an authentication bypass vulnerability when using XD or Intelligent-Management features.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.31 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29Patch SB0030823
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
IBM WebSphere Application Server deployments using XD or Intelligent-Management features are affected.
What type of impact does this vulnerability enable?
The issue is an authentication bypass vulnerability, meaning it may allow authentication controls to be bypassed in affected deployments.