CVE-2026-8644: IBM WebSphere Application Server is affected by an identity spoofing vulnerability
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
Other sources
IBM WebSphere Application Server is vulnerable to identity spoofing.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server (traditional) 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.30 - Upgrade
Upgrade
IBM WebSphere Application Server (traditional) 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71422
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8644?
The severity of CVE-2026-8644 is rated as critical with a score of 9.1.
How do I fix CVE-2026-8644?
To fix CVE-2026-8644, apply the currently available interim fix or fix pack that contains the fix for APAR PH71422.
Which versions of IBM WebSphere Application Server are affected by CVE-2026-8644?
CVE-2026-8644 affects IBM WebSphere Application Server versions 9.0 and 8.5.
What type of vulnerability is CVE-2026-8644?
CVE-2026-8644 is an identity spoofing vulnerability.
What impact does CVE-2026-8644 have on data integrity?
CVE-2026-8644 can lead to elevated privileges, thereby potentially compromising data integrity.