CVE-2026-10845
published 2026-06-22CVE-2026-10845: IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
PriorityP351high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.34%
26.0th percentile
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | 8.5.0 – 7.0.2 Interim Fix 035 | — |
| ibm | websphere_application_server | >= 8.5.0.0 < 8.5.5.30 | 8.5.5.30 |
| ibm | websphere_application_server | 9.0.0 – 7.0.3 Interim Fix 017 | — |
| ibm | websphere_application_server | >= 9.0.0.0 < 9.0.5.29 | 9.0.5.29 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
ghsa_unreviewed·2026-06-22
CVE-2026-10845 [HIGH] CWE-287 IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorized access to JAX-WS applications.
VulDB
IBM WebSphere Application Server up to 8.5/9.0 improper authentication
vuldb·2026-06-22·CVSS 7.3
CVE-2026-10845 [HIGH] IBM WebSphere Application Server up to 8.5/9.0 improper authentication
A vulnerability was found in IBM WebSphere Application Server up to 8.5/9.0. It has been declared as critical. This impacts an unknown function. Executing a manipulation can lead to improper authentication.
This vulnerability is registered as CVE-2026-10845. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-22
Published