CVE-2026-9311: IBM WebSphere Application Server is affected by remote code execution
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
Other sources
IBM WebSphere Application Server is vulnerable to remote code execution caused by the bypass of security controls.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 8.5.5.30 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade
IBM WebSphere Application Server traditionalto a version that resolves this vulnerability.Patch PH71453
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9311?
CVE-2026-9311 has a critical severity rating of 9.
What is CVE-2026-9311?
CVE-2026-9311 describes a remote code execution vulnerability in IBM WebSphere Application Server caused by the bypass of security controls.
How do I fix CVE-2026-9311?
To fix CVE-2026-9311, IBM recommends applying an interim fix or fix pack that addresses APAR PH71453.
Which versions of IBM WebSphere are affected by CVE-2026-9311?
CVE-2026-9311 affects IBM WebSphere Application Server versions 9.0 and 8.5.
What type of vulnerability is CVE-2026-9311?
CVE-2026-9311 is classified as a code injection vulnerability leading to remote code execution.