CVE-2026-9330: IBM WebSphere Application Server is affected by remote code execution
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.
Other sources
IBM WebSphere Application Server is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server traditional 8.5to a version that resolves this vulnerability.Fixed in 8.5.5.30 - Upgrade
Upgrade
IBM WebSphere Application Server traditional 9.0to a version that resolves this vulnerability.Fixed in 9.0.5.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch PH71453 - Operational
Apply the currently available interim fix or fix pack that contains the fix for APAR PH71453 to remediate the remote code execution issue in the SAML Web Single Sign-On deserialization path.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9330?
CVE-2026-9330 has a high severity score of 8.5.
How do I fix CVE-2026-9330?
To fix CVE-2026-9330, apply the currently available interim fix or fix pack that addresses APAR PH71453.
What type of vulnerability is CVE-2026-9330?
CVE-2026-9330 is a remote code execution vulnerability due to improper validation of user-supplied data.
Which versions of IBM WebSphere Application Server are affected by CVE-2026-9330?
CVE-2026-9330 affects IBM WebSphere Application Server versions 9.0 and 8.5.
What could be the impact of CVE-2026-9330 if exploited?
If exploited, CVE-2026-9330 could allow an attacker to execute arbitrary code remotely on the affected system.